S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2014-4942 Scanner

CVE-2014-4942 scanner - Information Disclosure vulnerability in The EasyCart plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2014-4942
5.0
CVSS

The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The EasyCart (wp-easycart) plugin is a popular e-commerce solution for WordPress websites. With this plugin, users can easily set up an online store and integrate various payment gateways to accept payments from customers. The EasyCart plugin offers a wide range of features, including product management, customer management, order management, and shipping management. This plugin is designed to make the e-commerce experience for retailers and customers hassle-free and efficient.

However, the EasyCart plugin is not without vulnerabilities. CVE-2014-4942 is one such vulnerability that was detected in the plugin. This vulnerability allowed remote attackers to obtain sensitive configuration information by making a direct request to inc/admin/phpinfo.php. This file invoked the phpinfo function, allowing attackers to obtain information about the PHP environment and the configuration settings used by the EasyCart plugin. The vulnerability was present in the plugin before version 2.0.6.

When exploited, the CVE-2014-4942 vulnerability can lead to sensitive information disclosure, putting the website at risk of cyber attacks. Attackers can use the information they obtain to plan targeted attacks and exploit other vulnerabilities in the system. This can lead to loss of valuable data, compromised website security, and financial harm. Therefore, it is important to protect against this vulnerability and take necessary precautions to ensure website security.

With the pro features of the s4e.io platform, website owners can easily and quickly learn about potential vulnerabilities in their digital assets. The platform offers advanced scanning and detection tools that can identify vulnerabilities in real-time, allowing website owners to take quick action to prevent cyber attacks. By using this service, website owners can ensure that their e-commerce platform is secure and protected from potential cyber threats.

 

REFERENCES

Solution Advice

To safeguard against the CVE-2014-4942 vulnerability, website owners can take the following precautions:

  • Keep the EasyCart plugin updated to the latest version
  • Restrict access to sensitive directories and files in the plugin
  • Implement strong login credentials and two-factor authentication
  • Limit the use of third-party plugins and themes
  • Regularly monitor website logs and suspicious activities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2014-4942 scanner - Information Disclosure vulnerability in The EasyCart plugin for WordPress | S4E