CVE-2015-3986 | TheCartPress eCommerce Shopping Cart up to 1.3.9.2 on WordPress wp-admin/admin.php tcp_box_path cross-site request forgery (Advisory 131673 / EDB-36860)
A vulnerability, which was classified as problematic, was found in TheCartPress eCommerce Shopping Cart up to 1.3.9.2 on WordPress. This affects an unknown part of the file wp-admin/admin.php. The manipulation of the argument tcp_box_path leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2015-3986. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.