Vulnerabilities > WP Olivecart

DATE CVE VULNERABILITY TITLE RISK
2017-05-22 CVE-2016-4905 SQL Injection vulnerability in Wp-Olivecart Olivecart and Olivecartpro
SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows attackers with administrator rights to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
wp-olivecart CWE-89
critical
9.8
2017-05-22 CVE-2016-4904 Cross-Site Request Forgery (CSRF) vulnerability in Wp-Olivecart Olivecart and Olivecartpro
Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to hijack the authentication of a user to perform unintended operations via unspecified vectors.
network
low complexity
wp-olivecart CWE-352
8.8
2017-05-22 CVE-2016-4903 Cross-site Scripting vulnerability in Wp-Olivecart Olivecart and Olivecartpro
Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
wp-olivecart CWE-79
6.1