🔙 목록으로 돌아가기

CVE-2019-25152: Abandoned Cart Lite for WooCommerce < 5.2.0 - Cross-Site Scripting

TitleAbandoned Cart Lite for WooCommerce < 5.2.0 - Cross-Site Scripting
AuthorDhiyaneshDK
SeverityHigh
ImpactThis makes it possible for unauthenticated attackers to inject arbitrary web scripts in user input that will execute on the admin dashboard.
RemediationFixed in 5.2.0
CVSS Score7.2
EPSS Score0.30617
CVE IDCVE-2019-25152
Shodan Queryhttp.html:"/wp-content/plugins/woocommerce-abandoned-cart/"
Fofa Querybody="/wp-content/plugins/woocommerce-abandoned-cart/"
Tags cve cve2019 wpscan wordpress wp wp-plugin woocommerce-abandoned-cart xss passive vkev vuln

🔍 Vulnerability Description

The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping.

🌐 HTTP Request

GET /wp-content/plugins/woocommerce-abandoned-cart/readme.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-25152.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-25152.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A