WP Shop [wp-shop-original] <= 3.9.6 (closed)
unknown[en] Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
- Disclosed:
- Sep 9, 2022
plugin
8 known security issues reported for the Wp Shop Original WordPress plugin. Most recent disclosed Sep 9, 2022.
Running Wp Shop Original on your site? Check whether your installed version is affected.
Scan your site free[en] Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.
The WP Shop plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on it's ajax function in versions up to, and including, 3.9.6. This makes it possible for unauthenticated attackers to change plugin settings and delete all orders and drop database tables.
The WP Shop plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via the ‘wpshop_email’ parameter in versions up to, and including, 3.4.3.18 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for unauthenticated atta...
The WP Shop plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via the ‘wpshop_email’ parameter in versions up to, and including, 3.4.3.18 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for unauthenticated atta...
The WP Shop plugin for WordPress is vulnerable to blind SQL Injection via the ‘wpshop_id’ parameter in versions up to, and including, 3.4.3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers t...
The WP Shop plugin for WordPress is vulnerable to blind SQL Injection via the ‘wpshop_id’ parameter in versions up to, and including, 3.4.3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers t...
The WP Shop WordPress plugin was affected by a Cross-Site Scripting (XSS) & CSRF security vulnerability.
The WP Shop WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free