CVE-2023-1124: Wpeasycart Wp Easycart
High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.
The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.
Affected products
- Wpeasycart Wp Easycart: before 5.4.3 (fixed in 5.4.3)
Published 2023-04-03. Last modified 2026-06-17.