CP Image Store with Slideshow <= 1.1.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Product Import
medium
The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9 due to a logic error in the 'cpis_admin_init' function's permission check. This makes it possible for authenticated attackers, with Contributor-level access and above, to import arbit...
- CVSS:
- 4.3
- Affected:
- up to 1.1.9
- Fixed in:
- 1.2.0
- Disclosed:
- Jan 12, 2026
CVE-2026-0684 on NVD →
CP Image Store with Slideshow [cp-image-store] < 1.0.68
unknown
[en] The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack
- Affected:
- up to 1.0.68
- Fixed in:
- 1.0.68
- Disclosed:
- Jun 6, 2022
CVE-2022-1692 on NVD →
CP Image Store with Slideshow <= 1.0.67 - Unauthenticated SQL Injection
critical
The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack
- CVSS:
- 9.8
- Affected:
- up to 1.0.68
- Fixed in:
- 1.0.68
- Disclosed:
- May 9, 2022
CVE-2022-1692 on NVD →
CP Image Store with Slideshow [cp-image-store] < 1.0.7
unknown
This plugin is prone to a purchase id brute force prevention vulnerability.
Update the plugin.
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
- Disclosed:
- Jul 13, 2015
CP Image Store with Slideshow < 1.0.6 - Arbitrary File Download
high
The CP Image Store with Slideshow plugin for WordPress is vulnerable to Directory Traversal in versions before 1.0.6 via the cpis_download_file function. This allows unauthenticated attackers to download arbitrary files from the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jul 10, 2015
CP Image Store with Slideshow < 1.0.7 - Arbitrary File Download
high
The CP Image Store with Slideshow plugin for WordPress is vulnerable to an Arbitrary File Download in versions up to, and including, 1.0.6. This is due to insufficient path validation on the 'f' parameter. This makes it possible for unauthenticated attackers to obtain Purchase IDs, and potentially use the IDs to exploi...
- CVSS:
- 7.5
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
- Disclosed:
- Jul 10, 2015
CP Image Store with Slideshow [cp-image-store] < 1.0.6
unknown
CP Image Store with Slideshow plugin is prone to an arbitrary file download vulnerability via "cp-image-store.php". It allows an attacker to download arbitrary files from the web server and get potentially sensitive information.
Update the plugin.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jul 10, 2015
CP Image Store with Slideshow [cp-image-store] < 1.0.6
unknown
The CP Image Store with Slideshow plugin for WordPress is vulnerable to Directory Traversal in versions before 1.0.6 via the cpis_download_file function. This allows unauthenticated attackers to download arbitrary files from the server, which can contain sensitive information.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jul 10, 2015
CP Image Store with Slideshow [cp-image-store] < 1.0.7
unknown
The CP Image Store with Slideshow plugin for WordPress is vulnerable to an Arbitrary File Download in versions up to, and including, 1.0.6. This is due to insufficient path validation on the 'f' parameter. This makes it possible for unauthenticated attackers to obtain Purchase IDs, and potentially use the IDs to exploi...
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
- Disclosed:
- Jul 10, 2015
CP Image Store with Slideshow [cp-image-store] < 1.0.7
unknown
The CP Image Store with Slideshow WordPress plugin was affected by a Purchase ID Brute Force Prevention security vulnerability.
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
CP Image Store with Slideshow [cp-image-store] < 1.0.6
unknown
The CP Image Store with Slideshow WordPress plugin was affected by an Arbitrary File Download security vulnerability.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database