Multiple vulnerabilities were discovered in TheCartPress WordPress plugin by Hich Tech Bridge Security Research Lab.
These holes can be used to execute arbitrary PHP code, revealing sensitive data, providing improper access control, as well as performing Cross-Site scripting attacks against users!
To exploit the local PHP File Inclusion vulnerability, an attacker would need to have administrator privileges on the WordPress. PHP does not properly check the URL before it is used in the 'include()', so it can be abused to include arbitrary local files via directory traversal sequences.
HTTP POST parameters are provided by many users during the checkout process. These parameters are not sanitized before being stored in the local database, and can be easily compromised by a non-authenticated attacker, who can inject malicious HTML and JS code that will be stored in the application's database at the following URL:
https://word press/wp-admin/admin-ajax.php?order_id=[order_id]&action=tcp_print_or der
Due to the broken authentication mechanism, any non-authenticated user can browse other users' commands. They can easily reproduce the command ID, which allows them to steal all existing commands.
The vulnerability can be reproduced by opening the following URL:
http://word press/shopping–cart/checkout/?tcp_checkout=ok&order_id=[order_id]
And the full command information can be viewed at the following URL:
https://word press/wp-admin/admin-ajax.php?order_id=[order_id]&action=tcp_print_or der
Inputs can be bypassed via the GET parameters “search_by“, “address_id“, “address_name“, “firstname“, “lastname“, “street“, “city“, “postcode“, “e-mail“, “post_id” and “rel_type”, and “post_type”. The above are not properly validated before being returned to the user, so the attacker can log in as an administrator, open a link, and execute arbitrary HTML and script code in the browser within the vulnerable site.

