eCommerce <= 3.15.1 - Cross-Site Request Forgery to Coupon Deletion
medium
The WP eCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.15.1. This is due to missing or incorrect nonce validation on the 'wpsc-product' post type page. This makes it possible for unauthenticated attackers to delete coupons via a forged request granted t...
- CVSS:
- 4.3
- Affected:
- up to 3.15.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 13, 2026
CVE-2026-1128 on NVD →
eCommerce <= 3.15.1 - Unauthenticated PHP Object Injection
high
The eCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.15.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via a...
- CVSS:
- 8.1
- Affected:
- up to 3.15.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 21, 2026
CVE-2026-1235 on NVD →
WP eCommerce [wp-e-commerce] <= 3.15.1 (unfixed + closed)
unknown
[en] The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...
- Affected:
- up to 3.15.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 28, 2024
CVE-2024-1514 on NVD →
WP eCommerce [wp-e-commerce] <= 3.15.1 (unfixed + closed)
unknown
[en] The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions up to, and including, 3.15.1. This makes it possible for unauthenticated attackers to create arbitrary posts with arbitrary content.
- Affected:
- up to 3.15.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 28, 2024
CVE-2024-1516 on NVD →
WP eCommerce <= 3.15.1 - Unauthenticated SQL Injection
critical
The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unaut...
- CVSS:
- 9.8
- Affected:
- up to 3.15.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 27, 2024
CVE-2024-1514 on NVD →
WP eCommerce <= 3.15.1 - Missing Authorization to Unauthenticated Arbitrary Post Creation
medium
The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions up to, and including, 3.15.1. This makes it possible for unauthenticated attackers to create arbitrary posts with arbitrary content.
- CVSS:
- 5.3
- Affected:
- up to 3.15.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 27, 2024
CVE-2024-1516 on NVD →
WP eCommerce < 3.11.4 - SQL Injection
high
The WP eCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘sessionid’ parameter in versions up to, and including, 3.11.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to ap...
- CVSS:
- 8.3
- Affected:
- up to 3.11.4
- Fixed in:
- 3.11.4
- Disclosed:
- Nov 12, 2016
WP eCommerce [wp-e-commerce] < 3.11.4 (closed)
unknown
The WP eCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘sessionid’ parameter in versions up to, and including, 3.11.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to ap...
- Affected:
- up to 3.11.4
- Fixed in:
- 3.11.4
- Disclosed:
- Nov 12, 2016
WP eCommerce <= 3.9.2 - Reflected Cross-Site Scripting
medium
The WP eCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'add_query_arg()' and 'remove_query_arg()' functions in versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 6.1
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.3
- Disclosed:
- Apr 20, 2015
WP eCommerce [wp-e-commerce] < 3.9.3 (closed)
unknown
The WP eCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'add_query_arg()' and 'remove_query_arg()' functions in versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.3
- Disclosed:
- Apr 20, 2015
WP eCommerce <= 3.8.14.3 - Missing Authorization
high
The WP eCommerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various functions called via AJAX actions and admin_init hooks in versions up to, and including, 3.8.14.3. This makes it possible for unauthenticated attackers to perform a plethora of actions like exporting...
- CVSS:
- 8.3
- Affected:
- up to 3.8.14.3
- Fixed in:
- 3.8.14.4
- Disclosed:
- Nov 1, 2014
WP eCommerce [wp-e-commerce] < 3.8.14.4 (closed)
unknown
The WP eCommerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various functions called via AJAX actions and admin_init hooks in versions up to, and including, 3.8.14.3. This makes it possible for unauthenticated attackers to perform a plethora of actions like exporting...
- Affected:
- up to 3.8.14.4
- Fixed in:
- 3.8.14.4
- Disclosed:
- Nov 1, 2014
WP eCommerce < 3.8.7.6 - SQL Injection
critical
SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVSS:
- 9.8
- Affected:
- up to 3.8.7.6
- Fixed in:
- 3.8.7.6
- Disclosed:
- Oct 5, 2014
CVE-2012-5310 on NVD →
WP eCommerce <= 3.8.9 - SQL Injection
critical
The WP eCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘view_purchlogs_by_status’ parameter in versions up to, and including, 3.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthen...
- CVSS:
- 9.8
- Affected:
- up to 3.8.9
- Fixed in:
- 3.8.9.1
- Disclosed:
- Aug 1, 2014
WP eCommerce <= 3.8.9 - Cross-Site Scripting
medium
The WP eCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the 'm' parameter in versions up to, and including, 3.8.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 3.8.9
- Fixed in:
- 3.8.9.1
- Disclosed:
- Aug 1, 2014
WP eCommerce [wp-e-commerce] < 3.8.9.1 (closed)
unknown
The WP eCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the 'm' parameter in versions up to, and including, 3.8.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 3.8.9.1
- Fixed in:
- 3.8.9.1
- Disclosed:
- Aug 1, 2014
WP eCommerce [wp-e-commerce] < 3.8.9.1 (closed)
unknown
The WP eCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘view_purchlogs_by_status’ parameter in versions up to, and including, 3.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthen...
- Affected:
- up to 3.8.9.1
- Fixed in:
- 3.8.9.1
- Disclosed:
- Aug 1, 2014
WP eCommerce [wp-e-commerce] <= 3.8.9.5 (closed)
unknown
WP e-Commerce plugin is prone to multiple security vulnerabilities, such as a local file include, arbitrary file upload and multiple remote code execution vulnerabilities. An attacker can upload arbitrary files to the affected computer that may result in arbitrary code execution within the context of the vulnerable app...
- Affected:
- up to 3.8.9.5
- Fixed in:
- 3.8.9.5
- Disclosed:
- Jan 24, 2014
WP eCommerce [wp-e-commerce] < 3.8.7.6 (closed)
unknown
[en] SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- Affected:
- up to 3.8.7.6
- Fixed in:
- 3.8.7.6
- Disclosed:
- Oct 8, 2012
CVE-2012-5310 on NVD →
WP eCommerce [wp-e-commerce] < 3.8.7.2 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possibly earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_text parameter. NOTE: some of these details are obtained from third party information.
- Affected:
- up to 3.8.7.2
- Fixed in:
- 3.8.7.2
- Disclosed:
- Aug 23, 2012
CVE-2011-5104 on NVD →
WP eCommerce < 3.8.7.2 - Stored Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possibly earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_text parameter. NOTE: some of these details are obtained from third party information.
- CVSS:
- 5.3
- Affected:
- up to 3.8.7.2
- Fixed in:
- 3.8.7.2
- Disclosed:
- Nov 21, 2011
CVE-2011-5104 on NVD →
WP eCommerce [wp-e-commerce] < 3.8.7 (closed)
unknown
This WordPress e-Commerce plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Upgrade the plugin.
- Affected:
- up to 3.8.7
- Fixed in:
- 3.8.7
- Disclosed:
- Sep 14, 2011
WP eCommerce [wp-e-commerce] <= 3.8.6 (closed)
unknown
WordPress WP e-Commerce plugin's "cart_messages[]" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-base...
- Affected:
- up to 3.8.6
- Fixed in:
- 3.8.6
- Disclosed:
- Aug 4, 2011
WP eCommerce [wp-e-commerce] < 3.11.4 (closed)
unknown
From vendor: "This vulnerability only affects users who use eWay as their payment gateway, have Gold Cart activated, and are using the as-of-yet-unreleased Theme Engine 2.0. We believe the number of users affected is likely close to zero, due to these conditions – but still, we highly recommend updating.&qu...
- Affected:
- up to 3.11.4
- Fixed in:
- 3.11.4
WP eCommerce [wp-e-commerce] < 3.9.3 (closed)
unknown
The WP eCommerce WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.3
WP eCommerce [wp-e-commerce] < 3.8.6.1 (closed)
unknown
The WP eCommerce WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected:
- up to 3.8.6.1
- Fixed in:
- 3.8.6.1
WP eCommerce [wp-e-commerce] < 3.8.12 (closed)
unknown
The WP eCommerce WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 3.8.12
- Fixed in:
- 3.8.12
WP eCommerce [wp-e-commerce] < 3.8.14.4 (closed)
unknown
The WP eCommerce WordPress plugin was affected by an Authorisation Bypass security vulnerability.
- Affected:
- up to 3.8.14.4
- Fixed in:
- 3.8.14.4
WP eCommerce [wp-e-commerce] < 3.8.8 (closed)
unknown
The WP eCommerce WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 3.8.8
- Fixed in:
- 3.8.8
WP eCommerce [wp-e-commerce] < 3.8.9.1 (closed)
unknown
The WP eCommerce WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected:
- up to 3.8.9.1
- Fixed in:
- 3.8.9.1
WP eCommerce [wp-e-commerce] < 3.8.9.1 (closed)
unknown
The WP eCommerce WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 3.8.9.1
- Fixed in:
- 3.8.9.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database