WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] < 2.4.1
unknown
[en] The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Nov 6, 2019
CVE-2014-9013 on NVD →
WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] < 2.4.1 (unfixed + closed)
unknown
[en] Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.
- Affected:
- up to 2.4.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2019
CVE-2014-9014 on NVD →
WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] < 1.2.2 (closed)
unknown
This plugin is prone to file enumeration weakness and file upload vulnerabilities. Because of them, attackers can disclose sensitive information, upload and execute arbitrary script code in the context of the webserver.
Update the plugin.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- May 15, 2015
WP Marketplace – Complete Shopping Cart / eCommerce Solution <= 2.4.0 - Arbitrary File Download
high
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.
- CVSS:
- 8.8
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Mar 21, 2015
CVE-2014-9013 on NVD →
Marketplace <= 2.4.0 - Path Traversal
medium
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.
- CVSS:
- 6.5
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Mar 21, 2015
CVE-2014-9014 on NVD →
WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] >= 1.5.0 - <= 1.6.1 (closed)
unknown
Marketplace plugin is prone to an arbitrary file upload vulnerability. Restricted access to this script is not properly realized. In that way an attacker can to upload files containing malicious PHP code and run it in the context of the web server process. Other attacks are also possible.
Update the plugin.
- Affected:
- 1.5.0 – 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Jun 5, 2012
WP Marketplace – Complete Shopping Cart / eCommerce Solution <= 1.2.1 - Arbitrary File Upload
critical
The WP Marketplace – Complete Shopping Cart / eCommerce Solution plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify/check.php and uploadify/uploadify.php files in versions up to, and including, 1.2.1. This makes it possible for attackers o upload arbitrary...
- CVSS:
- 9.8
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Apr 8, 2012
WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] < 1.2.2
unknown
The WP Marketplace – Complete Shopping Cart / eCommerce Solution plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify/check.php and uploadify/uploadify.php files in versions up to, and including, 1.2.1. This makes it possible for attackers o upload arbitrary...
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Apr 8, 2012
WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] <= 2.4.1 (unfixed + closed)
unknown
The wpmarketplace WordPress plugin was affected by an Arbitrary File Upload security vulnerability.
- Affected:
- up to 2.4.1
- Fix:
- No patched version reported
WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] < 1.2.2 (closed)
unknown
The wpmarketplace WordPress plugin was affected by a File Enumeration Weakness & File Upload Vulnerabilities security vulnerability.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
WP Marketplace – Complete Shopping Cart / eCommerce Solution [wpmarketplace] <= 1.5.0 (unfixed + closed)
unknown
The wpmarketplace WordPress plugin was affected by an Arbitrary File Upload security vulnerability.
- Affected:
- up to 1.5.0
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database