
Cloud Vulnerability DB
A community-led vulnerabilities database
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection (CVE-2024-3211) via the 'productid' attribute of the ec_addtocart shortcode in versions up to and including 5.6.3. This vulnerability was discovered and reported by Wordfence (Wordfence Report).
The vulnerability stems from insufficient escaping of user-supplied parameters and inadequate preparation of SQL queries. Specifically, the 'productid' attribute in the ec_addtocart shortcode is not properly sanitized, allowing for SQL injection attacks. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (Wordfence Report).
This vulnerability allows authenticated attackers with contributor-level access or higher to append additional SQL queries to existing queries, potentially enabling the extraction of sensitive information from the database (Wordfence Report).
The vulnerability requires authentication with contributor-level access or higher privileges to exploit. The attack vector is network-accessible, with low attack complexity and no user interaction required, as indicated by the CVSS metrics (Wordfence Report).
Website administrators running affected versions of the Shopping Cart & eCommerce Store plugin should update their installations immediately. A fix has been implemented in the plugin's repository (WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."