vulnerability

WordPress Plugin: usc-e-shop: CVE-2016-4828: Authentication Bypass Using an Alternate Path or Channel

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
Jun 24, 2016
Added
May 15, 2025
Modified
May 15, 2025

Description

The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to obtain access by leveraging knowledge of the e-mail address associated with an account.

Solution

usc-e-shop-plugin-cve-2016-4828
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.