CVE-2015-2673 | WP EasyCart Plugin up to 3.0.20 on WordPress admin_ajax_functions.php ec_ajax_update_option/ec_ajax_clear_all_taxrates option_name/option_value access control
A vulnerability was found in WP EasyCart Plugin up to 3.0.20 on WordPress and classified as critical. Affected by this issue is the function ec_ajax_update_option/ec_ajax_clear_all_taxrates of the file inc/admin/admin_ajax_functions.php. The manipulation of the argument option_name/option_value as part of Parameter leads to improper access controls.
This vulnerability is handled as CVE-2015-2673. The attack may be launched remotely. Furthermore, there is an exploit available.