The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to lack of randomization of a user controlled key. This makes it possible for unauthenticated attackers to access customer shopping carts and edit product links, add or delete products, and discover coupon codes.
Metrics
Affected Vendors & Products
References
History
Tue, 06 May 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tipsandtricks-hq
Tipsandtricks-hq wordpress Simple Paypal Shopping Cart |
|
CPEs | cpe:2.3:a:tipsandtricks-hq:wordpress_simple_paypal_shopping_cart:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Tipsandtricks-hq
Tipsandtricks-hq wordpress Simple Paypal Shopping Cart |
Thu, 01 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 01 May 2025 11:30:00 +0000

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-05-01T11:11:41.924Z
Updated: 2025-05-01T13:46:41.298Z
Reserved: 2025-04-22T16:33:30.164Z
Link: CVE-2025-3874

Updated: 2025-05-01T13:46:31.537Z

Status : Analyzed
Published: 2025-05-01T12:15:17.400
Modified: 2025-05-06T15:39:29.083
Link: CVE-2025-3874

No data.