plugin

Cp Image Store Vulnerabilities

11 known security issues reported for the Cp Image Store WordPress plugin. Most recent disclosed Jan 12, 2026.

1 critical 2 high 1 medium

Running Cp Image Store on your site? Check whether your installed version is affected.

Scan your site free

CP Image Store with Slideshow <= 1.1.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Product Import

medium

The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9 due to a logic error in the 'cpis_admin_init' function's permission check. This makes it possible for authenticated attackers, with Contributor-level access and above, to import arbit...

CVSS:
4.3
Affected:
up to 1.1.9
Fixed in:
1.2.0
Disclosed:
Jan 12, 2026

CVE-2026-0684 on NVD →

CP Image Store with Slideshow [cp-image-store] < 1.0.68

unknown

[en] The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack

Affected:
up to 1.0.68
Fixed in:
1.0.68
Disclosed:
Jun 6, 2022

CVE-2022-1692 on NVD →

CP Image Store with Slideshow <= 1.0.67 - Unauthenticated SQL Injection

critical

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack

CVSS:
9.8
Affected:
up to 1.0.68
Fixed in:
1.0.68
Disclosed:
May 9, 2022

CVE-2022-1692 on NVD →

CP Image Store with Slideshow [cp-image-store] < 1.0.7

unknown

This plugin is prone to a purchase id brute force prevention vulnerability. Update the plugin.

Affected:
up to 1.0.7
Fixed in:
1.0.7
Disclosed:
Jul 13, 2015

CP Image Store with Slideshow < 1.0.6 - Arbitrary File Download

high

The CP Image Store with Slideshow plugin for WordPress is vulnerable to Directory Traversal in versions before 1.0.6 via the cpis_download_file function. This allows unauthenticated attackers to download arbitrary files from the server, which can contain sensitive information.

CVSS:
7.5
Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Jul 10, 2015

CP Image Store with Slideshow < 1.0.7 - Arbitrary File Download

high

The CP Image Store with Slideshow plugin for WordPress is vulnerable to an Arbitrary File Download in versions up to, and including, 1.0.6. This is due to insufficient path validation on the 'f' parameter. This makes it possible for unauthenticated attackers to obtain Purchase IDs, and potentially use the IDs to exploi...

CVSS:
7.5
Affected:
up to 1.0.7
Fixed in:
1.0.7
Disclosed:
Jul 10, 2015

CP Image Store with Slideshow [cp-image-store] < 1.0.6

unknown

CP Image Store with Slideshow plugin is prone to an arbitrary file download vulnerability via "cp-image-store.php". It allows an attacker to download arbitrary files from the web server and get potentially sensitive information. Update the plugin.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Jul 10, 2015

CP Image Store with Slideshow [cp-image-store] < 1.0.6

unknown

The CP Image Store with Slideshow plugin for WordPress is vulnerable to Directory Traversal in versions before 1.0.6 via the cpis_download_file function. This allows unauthenticated attackers to download arbitrary files from the server, which can contain sensitive information.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Jul 10, 2015

CP Image Store with Slideshow [cp-image-store] < 1.0.7

unknown

The CP Image Store with Slideshow plugin for WordPress is vulnerable to an Arbitrary File Download in versions up to, and including, 1.0.6. This is due to insufficient path validation on the 'f' parameter. This makes it possible for unauthenticated attackers to obtain Purchase IDs, and potentially use the IDs to exploi...

Affected:
up to 1.0.7
Fixed in:
1.0.7
Disclosed:
Jul 10, 2015

CP Image Store with Slideshow [cp-image-store] < 1.0.7

unknown

The CP Image Store with Slideshow WordPress plugin was affected by a Purchase ID Brute Force Prevention security vulnerability.

Affected:
up to 1.0.7
Fixed in:
1.0.7

CP Image Store with Slideshow [cp-image-store] < 1.0.6

unknown

The CP Image Store with Slideshow WordPress plugin was affected by an Arbitrary File Download security vulnerability.

Affected:
up to 1.0.6
Fixed in:
1.0.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database