plugin

Eshop Vulnerabilities

13 known security issues reported for the Eshop WordPress plugin. Most recent disclosed Sep 25, 2019.

1 high 4 medium

Running Eshop on your site? Check whether your installed version is affected.

Scan your site free

eShop [eshop] < 6.3.14 (closed)

unknown

[en] The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.

Affected:
up to 6.3.14
Fixed in:
6.3.14
Disclosed:
Sep 25, 2019

CVE-2015-9413 on NVD →

eShop [eshop] < 6.3.12

unknown

[en] The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.

Affected:
up to 6.3.12
Fixed in:
6.3.12
Disclosed:
Jul 21, 2017

CVE-2015-3421 on NVD →

eShop [eshop] <= 6.3.14 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.

Affected:
up to 6.3.14
Fixed in:
6.3.14
Disclosed:
Jan 23, 2017

CVE-2016-0765 on NVD →

eShop [eshop] <= 6.3.14 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.

Affected:
up to 6.3.14
Fixed in:
6.3.14
Disclosed:
Jan 23, 2017

CVE-2016-0769 on NVD →

eShop <= 6.3.14 - Multiple SQL Injections

high

Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.

CVSS:
8.8
Affected:
up to 6.3.14
Fix:
No patched version reported
Disclosed:
Feb 2, 2016

CVE-2016-0769 on NVD →

eShop <= 6.3.14 - Multiple Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.

CVSS:
6.1
Affected:
up to 6.3.14
Fix:
No patched version reported
Disclosed:
Feb 2, 2016

CVE-2016-0765 on NVD →

eshop <= 6.3.13 - Cross-Site Forgery Request and Reflected Cross-Site Scripting

medium

The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.

CVSS:
6.5
Affected:
up to 6.3.13
Fixed in:
6.3.14
Disclosed:
Sep 9, 2015

CVE-2015-9413 on NVD →

eShop [eshop] < 6.3.14 (closed)

unknown

This plugin is prone to a cross site request forgery and cross site scripting vulnerabilities. Upgrade the plugin.

Affected:
up to 6.3.14
Fixed in:
6.3.14
Disclosed:
Sep 9, 2015

eShop <= 6.3.11 - Cross-Site Scripting

medium

The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.

CVSS:
6.1
Affected:
up to 6.3.12
Fixed in:
6.3.12
Disclosed:
May 6, 2015

CVE-2015-3421 on NVD →

eShop [eshop] < 6.2.9 (closed)

unknown

This WordPress eShop plugin is prone to multiple cross-site scripting vulnerabilities that fail to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credent...

Affected:
up to 6.2.9
Fixed in:
6.2.9
Disclosed:
Aug 10, 2011

eShop < 6.2.9 - Reflected Cross-Site Scripting

medium

The eshop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eshoptemplate’ GET parameter in versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.5
Affected:
up to 6.2.9
Fixed in:
6.2.9
Disclosed:
Jul 20, 2011

eShop [eshop] < 6.2.9

unknown

The eshop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eshoptemplate’ GET parameter in versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

Affected:
up to 6.2.9
Fixed in:
6.2.9
Disclosed:
Jul 20, 2011

eShop [eshop] < 6.2.9

unknown

The eshop WordPress plugin was affected by a wp-admin/admin.php Multiple Parameter XSS security vulnerability.

Affected:
up to 6.2.9
Fixed in:
6.2.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database