Security Flaw in WP eCommerce Plugin Allows Changing Purchase Information

  • 1 November 2014
  • 0 replies
  • 220 views

Userlevel 7
Badge +54
Private info on WordPress sites can be accessed and modified
By Ionut Ilascu on November 1st, 2014 A vulnerability in the popular shopping cart plug-in WP eCommerce for WordPress website publishing platform permits unauthorized modification of orders, making non-paid ones appear as paid as well as extraction of confidential customer information.
The glitch consists in the fact that the “admin_init” hook can be called without authentication; this is similar to the vulnerability in MailPoet plugin that was disclosed responsibly by Sucuri at the beginning of July and which was the cause of thousands of websites getting hacked by the end of the month. Full Article

0 replies

Be the first to reply!

Reply