English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

WordPress TheCartPress Plugin Order Information Security Bypass


Secunia ID

SA49652

Release Date

20 Jun 2012

Criticality

Less Critical

Solution Status

Vendor Patch

Software

WordPress TheCartPress Plugin 1.x

Where

From remote

Impact
Security Bypass

This covers vulnerabilities or security issues where malicious users or people can bypass certain security mechanisms of the application.

The actual impact varies significantly depending on the design and purpose of the affected application.

Description

Charlie Eriksen has discovered a vulnerability in the TheCartPress plugin for WordPress, which can be exploited by malicious people to bypass certain security restrictions.

The vulnerability is caused due to the wp-content/plugins/thecartpress/admin/PrintOrder.php script not checking for credentials before displaying order details. This can be exploited to view the order details of arbitrary users.

The vulnerability is confirmed in version 1.1.9.2. Other versions may also be affected.

Solution

The vendor has released an updated version 1.1.9.2, which fixes the vulnerability.

Reported by

Charlie Eriksen via Secunia.