eShop [eshop] < 6.3.14 (closed)
unknown
[en] The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
- Affected:
- up to 6.3.14
- Fixed in:
- 6.3.14
- Disclosed:
- Sep 25, 2019
CVE-2015-9413 on NVD →
eShop [eshop] < 6.3.12
unknown
[en] The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.
- Affected:
- up to 6.3.12
- Fixed in:
- 6.3.12
- Disclosed:
- Jul 21, 2017
CVE-2015-3421 on NVD →
eShop [eshop] <= 6.3.14 (closed)
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.
- Affected:
- up to 6.3.14
- Fixed in:
- 6.3.14
- Disclosed:
- Jan 23, 2017
CVE-2016-0765 on NVD →
eShop [eshop] <= 6.3.14 (closed)
unknown
[en] Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.
- Affected:
- up to 6.3.14
- Fixed in:
- 6.3.14
- Disclosed:
- Jan 23, 2017
CVE-2016-0769 on NVD →
eShop <= 6.3.14 - Multiple SQL Injections
high
Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.
- CVSS:
- 8.8
- Affected:
- up to 6.3.14
- Fix:
- No patched version reported
- Disclosed:
- Feb 2, 2016
CVE-2016-0769 on NVD →
eShop <= 6.3.14 - Multiple Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.
- CVSS:
- 6.1
- Affected:
- up to 6.3.14
- Fix:
- No patched version reported
- Disclosed:
- Feb 2, 2016
CVE-2016-0765 on NVD →
eshop <= 6.3.13 - Cross-Site Forgery Request and Reflected Cross-Site Scripting
medium
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
- CVSS:
- 6.5
- Affected:
- up to 6.3.13
- Fixed in:
- 6.3.14
- Disclosed:
- Sep 9, 2015
CVE-2015-9413 on NVD →
eShop [eshop] < 6.3.14 (closed)
unknown
This plugin is prone to a cross site request forgery and cross site scripting vulnerabilities.
Upgrade the plugin.
- Affected:
- up to 6.3.14
- Fixed in:
- 6.3.14
- Disclosed:
- Sep 9, 2015
eShop <= 6.3.11 - Cross-Site Scripting
medium
The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.
- CVSS:
- 6.1
- Affected:
- up to 6.3.12
- Fixed in:
- 6.3.12
- Disclosed:
- May 6, 2015
CVE-2015-3421 on NVD →
eShop [eshop] < 6.2.9 (closed)
unknown
This WordPress eShop plugin is prone to multiple cross-site scripting vulnerabilities that fail to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credent...
- Affected:
- up to 6.2.9
- Fixed in:
- 6.2.9
- Disclosed:
- Aug 10, 2011
eShop < 6.2.9 - Reflected Cross-Site Scripting
medium
The eshop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eshoptemplate’ GET parameter in versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...
- CVSS:
- 6.5
- Affected:
- up to 6.2.9
- Fixed in:
- 6.2.9
- Disclosed:
- Jul 20, 2011
eShop [eshop] < 6.2.9
unknown
The eshop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eshoptemplate’ GET parameter in versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...
- Affected:
- up to 6.2.9
- Fixed in:
- 6.2.9
- Disclosed:
- Jul 20, 2011
eShop [eshop] < 6.2.9
unknown
The eshop WordPress plugin was affected by a wp-admin/admin.php Multiple Parameter XSS security vulnerability.
- Affected:
- up to 6.2.9
- Fixed in:
- 6.2.9
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database