CVE-2025-3874

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to lack of randomization of a user controlled key. This makes it possible for unauthenticated attackers to access customer shopping carts and edit product links, add or delete products, and discover coupon codes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tipsandtricks-hq:wordpress_simple_paypal_shopping_cart:*:*:*:*:*:wordpress:*:*

History

06 May 2025, 15:39

Type Values Removed Values Added
References () https://developer.wordpress.org/reference/functions/wp_generate_password/ - () https://developer.wordpress.org/reference/functions/wp_generate_password/ - Product
References () https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/includes/class-wpsc-cart.php#L32 - () https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/includes/class-wpsc-cart.php#L32 - Product
References () https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/includes/class-wpsc-cart.php#L68 - () https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/includes/class-wpsc-cart.php#L68 - Product
References () https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/wp_shopping_cart.php#L158 - () https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/wp_shopping_cart.php#L158 - Product
References () https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/wp_shopping_cart.php#L265 - () https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/wp_shopping_cart.php#L265 - Product
References () https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/wp_shopping_cart.php#L525 - () https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/wp_shopping_cart.php#L525 - Product
References () https://plugins.trac.wordpress.org/changeset/3284572/ - () https://plugins.trac.wordpress.org/changeset/3284572/ - Patch
References () https://www.tipsandtricks-hq.com/ecommerce/wp-shopping-cart - () https://www.tipsandtricks-hq.com/ecommerce/wp-shopping-cart - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/4fed59bf-885b-4a06-aff2-8e5ab5f83ba7?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/4fed59bf-885b-4a06-aff2-8e5ab5f83ba7?source=cve - Third Party Advisory
Summary
  • (es) El complemento Simple Shopping Cart para WordPress es vulnerable a una Referencia Directa a Objetos Insegura en todas las versiones hasta la 5.1.3 incluida, debido a la falta de aleatorización de una clave controlada por el usuario. Esto permite a atacantes no autenticados acceder a los carritos de compra de los clientes, editar enlaces de productos, añadir o eliminar productos y descubrir códigos de cupón.
CPE cpe:2.3:a:tipsandtricks-hq:wordpress_simple_paypal_shopping_cart:*:*:*:*:*:wordpress:*:*
First Time Tipsandtricks-hq
Tipsandtricks-hq wordpress Simple Paypal Shopping Cart

01 May 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 12:15

Updated : 2025-05-06 15:39


NVD link : CVE-2025-3874

Mitre link : CVE-2025-3874

CVE.ORG link : CVE-2025-3874


JSON object : View

Products Affected

tipsandtricks-hq

  • wordpress_simple_paypal_shopping_cart
CWE
CWE-639

Authorization Bypass Through User-Controlled Key