peter bassill · operator
$ cve CVE-2013-5977 JSON

CVE-2013-5977 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 3.2% (pctl 88)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers to hijack the authentication of administrators for requests that (1) create or modify products or conduct cross-site scripting (XSS) attacks via the (2) Product name or (3) Price description field in a product save action via a request to wp-admin/admin.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS3.15% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2013-11-01
Last modified2026-06-16

Affected (1)

VendorProduct
cart66cart66 lite plugin

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD