plugin

Wpmarketplace Vulnerabilities

11 known security issues reported for the Wpmarketplace WordPress plugin. Most recent disclosed Nov 6, 2019.

1 critical 1 high 1 medium

Running Wpmarketplace on your site? Check whether your installed version is affected.

Scan your site free

WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] < 2.4.1

unknown

[en] The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Nov 6, 2019

CVE-2014-9013 on NVD →

WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] < 2.4.1 (unfixed + closed)

unknown

[en] Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.

Affected:
up to 2.4.1
Fix:
No patched version reported
Disclosed:
Nov 6, 2019

CVE-2014-9014 on NVD →

WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] < 1.2.2 (closed)

unknown

This plugin is prone to file enumeration weakness and file upload vulnerabilities. Because of them, attackers can disclose sensitive information, upload and execute arbitrary script code in the context of the webserver. Update the plugin.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
May 15, 2015

WP Marketplace – Complete Shopping Cart / eCommerce Solution <= 2.4.0 - Arbitrary File Download

high

The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.

CVSS:
8.8
Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Mar 21, 2015

CVE-2014-9013 on NVD →

Marketplace <= 2.4.0 - Path Traversal

medium

Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.

CVSS:
6.5
Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Mar 21, 2015

CVE-2014-9014 on NVD →

WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] >= 1.5.0 - <= 1.6.1 (closed)

unknown

Marketplace plugin is prone to an arbitrary file upload vulnerability. Restricted access to this script is not properly realized. In that way an attacker can to upload files containing malicious PHP code and run it in the context of the web server process. Other attacks are also possible. Update the plugin.

Affected:
1.5.0 – 1.6.1
Fixed in:
1.6.1
Disclosed:
Jun 5, 2012

WP Marketplace – Complete Shopping Cart / eCommerce Solution <= 1.2.1 - Arbitrary File Upload

critical

The WP Marketplace – Complete Shopping Cart / eCommerce Solution plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify/check.php and uploadify/uploadify.php files in versions up to, and including, 1.2.1. This makes it possible for attackers o upload arbitrary...

CVSS:
9.8
Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Apr 8, 2012

WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] < 1.2.2

unknown

The WP Marketplace – Complete Shopping Cart / eCommerce Solution plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify/check.php and uploadify/uploadify.php files in versions up to, and including, 1.2.1. This makes it possible for attackers o upload arbitrary...

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Apr 8, 2012

WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] <= 2.4.1 (unfixed + closed)

unknown

The wpmarketplace WordPress plugin was affected by an Arbitrary File Upload security vulnerability.

Affected:
up to 2.4.1
Fix:
No patched version reported

WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] < 1.2.2 (closed)

unknown

The wpmarketplace WordPress plugin was affected by a File Enumeration Weakness &amp; File Upload Vulnerabilities security vulnerability.

Affected:
up to 1.2.2
Fixed in:
1.2.2

WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] <= 1.5.0 (unfixed + closed)

unknown

The wpmarketplace WordPress plugin was affected by an Arbitrary File Upload security vulnerability.

Affected:
up to 1.5.0
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database