The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| levelfourdevelopment | wp-easycart | 2.0.1 |
| levelfourdevelopment | wp-easycart | 2.0.4 |
| levelfourdevelopment | wp-easycart | * |
| levelfourdevelopment | wp-easycart | 2.0.2 |
| levelfourdevelopment | wp-easycart | 2.0.3 |