Ultimate Product Catalog <= 4.4.48 - Authenticated (Contributor+) Arbitrary File Upload
high
The Ultimate Product Catalog plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.4.48. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server...
- CVSS:
- 8.8
- Affected:
- up to 4.4.48
- Fixed in:
- 5.0.0
- Disclosed:
- Jun 15, 2026
CVE-2016-20075 on NVD →
Ultimate Product Catalog [ultimate-product-catalogue] < 5.2.16
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Ultimate Product Catalogue.This issue affects Ultimate Product Catalogue: from n/a through 5.2.15.
- Affected:
- up to 5.2.16
- Fixed in:
- 5.2.16
- Disclosed:
- Apr 15, 2024
CVE-2024-31921 on NVD →
Ultimate Product Catalogue <= 5.2.15 - Cross-Site Request Forgery via reset_settings()
medium
The Ultimate Product Catalogue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.15. This is due to missing or incorrect nonce validation on the reset_settings() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forge...
- CVSS:
- 4.3
- Affected:
- up to 5.2.15
- Fixed in:
- 5.2.16
- Disclosed:
- Apr 10, 2024
CVE-2024-31921 on NVD →
Ultimate Product Catalog [ultimate-product-catalogue] < 5.2.6
unknown
[en] The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.6
- Disclosed:
- Jun 27, 2023
CVE-2023-2711 on NVD →
Ultimate Product Catalog <= 5.2.5 - Authenticated(Administrator+) Stored Cross-Site Scripting
medium
The Ultimate Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...
- CVSS:
- 4.4
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Jun 5, 2023
CVE-2023-2711 on NVD →
Ultimate Product Catalog [ultimate-product-catalogue] < 5.0.26
unknown
[en] The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example
- Affected:
- up to 5.0.26
- Fixed in:
- 5.0.26
- Disclosed:
- Feb 7, 2022
CVE-2021-24993 on NVD →
Ultimate Product Catalog – WordPress Catalog Plugin <= 5.0.25 - Cross-Site Request Forgery
medium
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example
- CVSS:
- 6.5
- Affected:
- up to 5.0.26
- Fixed in:
- 5.0.26
- Disclosed:
- Jan 6, 2022
CVE-2021-24993 on NVD →
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.26
unknown
A vulnerability exists in UPCP_Add_To_Cart() function. There the cookie is unserialized which means an attacker can create a malicious user input to create a PHP object injection.
- Affected:
- up to 4.2.26
- Fixed in:
- 4.2.26
- Disclosed:
- Oct 30, 2017
Ultimate Product Catalog <= 4.2.21 - Authorization Bypass and Cross-Site Request Forgery
high
The Ultimate Product Catalog plugin for WordPress is vulnerable to authorization bypass and Cross-Site Request Forgery in versions up to, and including 4.2.21 due to missing capability and nonce checking on various functions. This makes it possible for authenticated attackers to perform a wide variety of actions such a...
- CVSS:
- 8.8
- Affected:
- up to 4.2.21
- Fixed in:
- 4.2.22
- Disclosed:
- Oct 3, 2017
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.22
unknown
The Ultimate Product Catalog plugin for WordPress is vulnerable to authorization bypass and Cross-Site Request Forgery in versions up to, and including 4.2.21 due to missing capability and nonce checking on various functions. This makes it possible for authenticated attackers to perform a wide variety of actions such a...
- Affected:
- up to 4.2.22
- Fixed in:
- 4.2.22
- Disclosed:
- Oct 3, 2017
Ultimate Product Catalog <= 4.2.22 - SQL Injection
critical
The Etoile Ultimate Product Catalog plugin 4.2.22 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_item, category_products_update_order category-product-item, custom...
- CVSS:
- 9.8
- Affected:
- up to 4.2.22
- Fixed in:
- 4.2.23
- Disclosed:
- Aug 1, 2017
CVE-2017-12199 on NVD →
Ultimate Product Catalog <= 4.2.11 - Cross-Site Scripting
medium
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.
- CVSS:
- 6.1
- Affected:
- up to 4.2.11
- Fixed in:
- 4.2.12
- Disclosed:
- Aug 1, 2017
CVE-2017-12200 on NVD →
Ultimate Product Catalog < 4.2.3 - Authenticated SQL Injection
medium
The Ultimate Product Catalog plugin for WordPress is vulnerable to SQL Injection via the ‘CatID’ parameter in versions before 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append addit...
- CVSS:
- 5.4
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Jun 27, 2017
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.3
unknown
The Ultimate Product Catalog plugin for WordPress is vulnerable to SQL Injection via the ‘CatID’ parameter in versions before 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append addit...
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Jun 27, 2017
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.3
unknown
WordPress Ultimate Product Catalogue plugin vulnerable to SQL Injection due to unescaped $_POST[‘CatID’]
Change log of the plugin doesn't indicate any fixes related to this vulnerability. We will update information soon.
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Jun 27, 2017
Ultimate Product Catalog [ultimate-product-catalogue] < 3.9.9
unknown
This plugin is prone to an SQL injection vulnerability via ajax. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 3.9.9
- Fixed in:
- 3.9.9
- Disclosed:
- Jul 29, 2016
Ultimate Product Catalog [ultimate-product-catalogue] < 3.4
unknown
This WordPress Ultimate Membership Pro plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update WordPress plugin to the newest stable and safe version.
- Affected:
- up to 3.4
- Fixed in:
- 3.4
- Disclosed:
- Jun 29, 2016
Ultimate Product Catalog [ultimate-product-catalogue] < 3.8.7
unknown
Because of this vulnerability, an attacker can upload arbitrary files to WordPress upload directory and manage this plugin with an especific account.
Upgrade the plugin.
- Affected:
- up to 3.8.7
- Fixed in:
- 3.8.7
- Disclosed:
- Jun 27, 2016
Ultimate Product Catalog [ultimate-product-catalogue] < 3.8.2
unknown
Ultimate Product Catalog plugin is prone to a privilege escalation vulnerability in the "<upc-plugin-path>/Functions/Update_Admin-Databases.php" file. It allows an attacker to manage the administration page and have an especific account.
Upgrade the plugin.
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
- Disclosed:
- Jun 20, 2016
Ultimate Product Catalog <= 3.8.1 - Missing Authorization to Plugin Settings Update
medium
The Ultimate Product Catalog plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the Update_UPCP_Options() function in versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with contributor-level permissions and above, to edit plugin settin...
- CVSS:
- 4.3
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
- Disclosed:
- Jun 17, 2016
Ultimate Product Catalog [ultimate-product-catalogue] < 3.8.2
unknown
The Ultimate Product Catalog plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the Update_UPCP_Options() function in versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with contributor-level permissions and above, to edit plugin settin...
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
- Disclosed:
- Jun 17, 2016
Ultimate Product Catalogue < 3.1.3 - SQL Injection
critical
The Ultimate Product Catalogue for WordPress is vulnerable to SQL Injection via the ‘Item_ID’ and 'SingleProduct' parameters in versions before 3.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...
- CVSS:
- 9.8
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Jun 7, 2015
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3
unknown
The Ultimate Product Catalogue for WordPress is vulnerable to SQL Injection via the ‘Item_ID’ and 'SingleProduct' parameters in versions before 3.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Jun 7, 2015
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3
unknown
Ultimate Product Catalogue plugin is prone to persistent cross-site scripting, cross-site request forgery and file upload vulnerabilities.
Update the WordPress Ultimate Product Catalogue plugin to the latest version (at least 3.1.3)
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- May 4, 2015
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3
unknown
This WordPress Ultimate Product Catalogue plugin's "SingleProduct" parameter is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the WordPress Ultimate Product Catalogue plugin to...
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Apr 23, 2015
Ultimate Product Catalog < 4.2.22 - Arbitrary File Upload
critical
The Ultimate Product Catalog plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Functions/Prepare_Data_For_Insertion.php file in versions up to, and including, 4.2.22. This makes it possible for unauthenticated attackers (before version 3.1.2) and authenticated attac...
- CVSS:
- 9.8
- Affected:
- up to 4.2.22
- Fixed in:
- 4.2.22
- Disclosed:
- Apr 22, 2015
Ultimate Product Catalog < 3.1.3 - Multiple Vulnerabilities
high
The Ultimate Product Catalog plugin for WordPress has multiple vulnerabilities in versions up to, and including, 3.1.2. This is due to a lack of sanitization of user input and insufficient checks on file types. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 8.8
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Apr 22, 2015
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.22
unknown
The Ultimate Product Catalog plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Functions/Prepare_Data_For_Insertion.php file in versions up to, and including, 4.2.22. This makes it possible for unauthenticated attackers (before version 3.1.2) and authenticated attac...
- Affected:
- up to 4.2.22
- Fixed in:
- 4.2.22
- Disclosed:
- Apr 22, 2015
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3
unknown
The Ultimate Product Catalog plugin for WordPress has multiple vulnerabilities in versions up to, and including, 3.1.2. This is due to a lack of sanitization of user input and insufficient checks on file types. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Apr 22, 2015
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.2
unknown
Remote unauthenticated attacker can exploit this issue by sending a specially-crafted HTTP POST request.
Update the plugin.
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Apr 22, 2015
Ultimate Product Catalog < 2.1.1 - Authenticated (Admin+) SQL Injection
high
The Ultimate Product Catalog plugin for WordPress is vulnerable to generic SQL Injection via the Catalogue_ID, SubCategory_ID, SingleProduct, & Tag_ID parameters in versions up to, and including, 2.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL que...
- CVSS:
- 7.2
- Affected:
- up to 2.1
- Fixed in:
- 2.1.1
- Disclosed:
- May 28, 2014
Ultimate Product Catalog [ultimate-product-catalogue] < 2.1.1
unknown
The Ultimate Product Catalog plugin for WordPress is vulnerable to generic SQL Injection via the Catalogue_ID, SubCategory_ID, SingleProduct, & Tag_ID parameters in versions up to, and including, 2.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL que...
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- May 28, 2014
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.2
unknown
By sending a specially-crafted HTTP POST request, a remote unauthenticated attacker can exploit this issue to upload arbitrary file and execute it in the context of the web server process.
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3
unknown
Unauthenticated SQL injection in ajax call when the plugin is counting the times a product is being seen by the web visitors. The vulnerable POST parameter is "Item_ID".
Vulnerable code:
In file Functions/Process_Ajax.php line 67:
[...]
$Item_ID = $_POST['Item_ID'];
$Item = $wpdb->ge...
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3
unknown
Unauthenticated SQL injection in parameter "SingleProduct" when a web visitor explores a product published by the web administrator. This exploit needs magic_quotes_gpc turned off in the destination server.
File Functions/Shortcodes.php line 779
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.5
unknown
Product Name and Description and File Upload formulary of plugin Ultimate Product Catalog lacks of proper CSRF protection and proper filtering. Allowing an attacker to alter a product presented to a customer or the wordpress administrators and insert XSS in his product name and description. It also allows an attacker t...
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
Ultimate Product Catalog [ultimate-product-catalogue] < 3.9.9
unknown
The Ultimate Product Catalog – WordPress Catalog Plugin WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.
- Affected:
- up to 3.9.9
- Fixed in:
- 3.9.9
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.3
unknown
Type user access: subscriber upwards.
$_POST[‘CatID’] is not escaped.
File / Code:
Path: /wp-content/plugins/ultimate-product-catalogue/Functions/Process_Ajax.php
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3