plugin

Wp Shop Original Vulnerabilities

8 known security issues reported for the Wp Shop Original WordPress plugin. Most recent disclosed Sep 9, 2022.

2 critical 1 high

Running Wp Shop Original on your site? Check whether your installed version is affected.

Scan your site free

WP Shop [wp-shop-original] <= 3.9.6 (closed)

unknown

[en] Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.

Affected:
up to 3.9.6
Fixed in:
3.9.6
Disclosed:
Sep 9, 2022

CVE-2022-36793 on NVD →

WP Shop <= 3.9.6 - Missing Authentication to Settings Change and Order Deletion

critical

The WP Shop plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on it's ajax function in versions up to, and including, 3.9.6. This makes it possible for unauthenticated attackers to change plugin settings and delete all orders and drop database tables.

CVSS:
9.8
Affected:
up to 3.9.6
Fix:
No patched version reported
Disclosed:
Aug 31, 2022

CVE-2022-36793 on NVD →

WP Shop <= 3.4.3.18 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

The WP Shop plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via the ‘wpshop_email’ parameter in versions up to, and including, 3.4.3.18 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for unauthenticated atta...

CVSS:
8.8
Affected:
up to 3.4.3.19
Fixed in:
3.4.3.19
Disclosed:
Sep 14, 2015

WP Shop [wp-shop-original] < 3.4.3.19 (closed)

unknown

The WP Shop plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via the ‘wpshop_email’ parameter in versions up to, and including, 3.4.3.18 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for unauthenticated atta...

Affected:
up to 3.4.3.19
Fixed in:
3.4.3.19
Disclosed:
Sep 14, 2015

WP Shop < 3.4.3.16 - SQL Injection

critical

The WP Shop plugin for WordPress is vulnerable to blind SQL Injection via the ‘wpshop_id’ parameter in versions up to, and including, 3.4.3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers t...

CVSS:
9.8
Affected:
up to 3.4.3.16
Fixed in:
3.4.3.16
Disclosed:
Jul 8, 2015

WP Shop [wp-shop-original] < 3.4.3.16 (closed)

unknown

The WP Shop plugin for WordPress is vulnerable to blind SQL Injection via the ‘wpshop_id’ parameter in versions up to, and including, 3.4.3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers t...

Affected:
up to 3.4.3.16
Fixed in:
3.4.3.16
Disclosed:
Jul 8, 2015

WP Shop [wp-shop-original] < 3.4.3.19 (closed)

unknown

The WP Shop WordPress plugin was affected by a Cross-Site Scripting (XSS) &amp; CSRF security vulnerability.

Affected:
up to 3.4.3.19
Fixed in:
3.4.3.19

WP Shop [wp-shop-original] < 3.4.3.16 (closed)

unknown

The WP Shop WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.

Affected:
up to 3.4.3.16
Fixed in:
3.4.3.16

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database