plugin

Wp Ecommerce Shop Styling Vulnerabilities

7 known security issues reported for the Wp Ecommerce Shop Styling WordPress plugin. Most recent disclosed May 23, 2017.

1 critical 1 high

Running Wp Ecommerce Shop Styling on your site? Check whether your installed version is affected.

Scan your site free

WP e-Commerce Shop Styling [wp-ecommerce-shop-styling] < 2.6 (closed)

unknown

[en] Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php.

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
May 23, 2017

CVE-2015-5468 on NVD →

WP e-Commerce Shop Styling [wp-ecommerce-shop-styling] < 2.6 (closed)

unknown

This plugin is prone to a local file inclusion vulnerability, becuse the code in ./wp-ecommerce-shop-styling/includes/download.php is not sanitized. Update the plugin.

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Sep 20, 2015

WP e-Commerce Shop Styling [wp-ecommerce-shop-styling] < 2.6 (closed)

unknown

E-Commerce Shop Styling plugin is prone to an arbitrary file upload vulnerability. It allows an attacker to upload arbitrary files to the affected computer. Upgrade the plugin.

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Jul 8, 2015

WP eCommerce Shop Styling < 2.6 - Directory Traversal

high

Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php.

CVSS:
7.5
Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Jul 5, 2015

CVE-2015-5468 on NVD →

WP e-Commerce Shop Styling [wp-ecommerce-shop-styling] < 1.8 (closed)

unknown

[en] PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote attackers to execute arbitrary PHP code via a URL in the dompdf parameter.

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
May 27, 2014

CVE-2013-0724 on NVD →

WP e-Commerce Shop Styling [wp-ecommerce-shop-styling] <= 2.9.1 (closed)

unknown

[en] dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file paramet...

Affected:
up to 2.9.1
Fixed in:
2.9.1
Disclosed:
Apr 28, 2014

CVE-2014-2383 on NVD →

WP eCommerce Shop Styling < 1.8 - Remote File Inclusion

critical

PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote attackers to execute arbitrary PHP code via a URL in the dompdf parameter.

CVSS:
9.8
Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Feb 6, 2013

CVE-2013-0724 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database