The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Wp_easycart | Wpeasycart | * | 5.4.3 (excluding) |
References