WP e-Commerce Shop Styling [wp-ecommerce-shop-styling] < 2.6 (closed)
unknown
[en] Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php.
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- May 23, 2017
CVE-2015-5468 on NVD →
WP e-Commerce Shop Styling [wp-ecommerce-shop-styling] < 2.6 (closed)
unknown
This plugin is prone to a local file inclusion vulnerability, becuse the code in ./wp-ecommerce-shop-styling/includes/download.php is not sanitized.
Update the plugin.
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Sep 20, 2015
WP e-Commerce Shop Styling [wp-ecommerce-shop-styling] < 2.6 (closed)
unknown
E-Commerce Shop Styling plugin is prone to an arbitrary file upload vulnerability. It allows an attacker to upload arbitrary files to the affected computer.
Upgrade the plugin.
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Jul 8, 2015
WP eCommerce Shop Styling < 2.6 - Directory Traversal
high
Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php.
- CVSS:
- 7.5
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Jul 5, 2015
CVE-2015-5468 on NVD →
WP e-Commerce Shop Styling [wp-ecommerce-shop-styling] < 1.8 (closed)
unknown
[en] PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote attackers to execute arbitrary PHP code via a URL in the dompdf parameter.
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 27, 2014
CVE-2013-0724 on NVD →
WP e-Commerce Shop Styling [wp-ecommerce-shop-styling] <= 2.9.1 (closed)
unknown
[en] dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file paramet...
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Apr 28, 2014
CVE-2014-2383 on NVD →
WP eCommerce Shop Styling < 1.8 - Remote File Inclusion
critical
PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote attackers to execute arbitrary PHP code via a URL in the dompdf parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- Feb 6, 2013
CVE-2013-0724 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database