What the vulnerability does
01Description
Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.
Explanation of Vulnerability in Simple Terms
The Api2Cart Bridge Connector WordPress plugin version 1.1.0 and earlier contains a critical vulnerability that allows unauthenticated attackers to execute arbitrary code on the site. No special conditions or user interaction are required. The vulnerability affects the entire WordPress installation and any connected systems.
What an attacker can do
Run their own code on the WordPress site and connected systems without logging in.
Potential impact on your site
Complete compromise of the WordPress site, database, and any systems connected via Api2Cart.
Conditions required to exploit
Network access to the WordPress site. No authentication or user interaction required.
Key dates
External resources