CVE-2014-4942: Levelfourdevelopment Wp-Easycart

Medium severity, CVSS 5.0. EPSS: 4.5% chance of exploitation in the next 30 days.

The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function.

Affected products

  • Levelfourdevelopment Wp-Easycart: up to and including 2.0.5; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only

Published 2014-07-11. Last modified 2026-06-17.