WPshop 2 – E-Commerce [wpshop] <= 2.6.1 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows PHP Local File Inclusion.This issue affects WP shop: from n/a through <= 2.6.1.
- Affected:
- up to 2.6.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2025-69383 on NVD →
shop <= 2.6.1 - Unauthenticated Local File Inclusion
high
The shop plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtai...
- CVSS:
- 8.1
- Affected:
- up to 2.6.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 9, 2026
CVE-2025-69383 on NVD →
WPshop 2 – E-Commerce [wpshop] < 1.3.9.6
unknown
[en] The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code ex...
- Affected:
- up to 1.3.9.6
- Fixed in:
- 1.3.9.6
- Disclosed:
- Jul 19, 2025
CVE-2015-10135 on NVD →
WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover
high
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email & password through the update() function. This makes it possible for authen...
- CVSS:
- 8.8
- Affected:
- 2.0.0 – 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- May 6, 2025
CVE-2025-3852 on NVD →
WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Key Generation
medium
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.6.0 via the callback_generate_api_key() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create valid...
- CVSS:
- 5.4
- Affected:
- 2.0.0 – 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- May 6, 2025
CVE-2025-3853 on NVD →
WP shop <= 2.6.0 - Cross-Site Request Forgery to Arbitrary File Upload
high
The WP shop plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site admi...
- CVSS:
- 8.8
- Affected:
- up to 2.6.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2025
CVE-2025-32576 on NVD →
WPshop 2 – E-Commerce [wpshop] <= 2.6.0 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop allows Upload a Web Shell to a Web Server. This issue affects WP shop: from n/a through 2.6.0.
- Affected:
- up to 2.6.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2025
CVE-2025-32576 on NVD →
WPshop 2 – E-Commerce [wpshop] < 3.4.3.19
unknown
This plugin is prone to cross site scripting and cross site request forgery vulnerabilities.
Update the plugin.
- Affected:
- up to 3.4.3.19
- Fixed in:
- 3.4.3.19
- Disclosed:
- Sep 17, 2015
WPshop 2 – E-Commerce [wpshop] < 3.4.3.16
unknown
This plugin is prone to an SQL injection via "wpshop_id" parameter.
Update the plugin.
- Affected:
- up to 3.4.3.16
- Fixed in:
- 3.4.3.16
- Disclosed:
- Jul 8, 2015
WPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File Upload
critical
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code executi...
- CVSS:
- 9.8
- Affected:
- up to 1.3.9.6
- Fixed in:
- 1.3.9.6
- Disclosed:
- Mar 9, 2015
CVE-2015-10135 on NVD →
WPshop 2 – E-Commerce [wpshop] < 1.3.9.6
unknown
This plugin is prone to an arbitrary file upload vulnerability during "ajaxUpload" action.
Update the plugin.
- Affected:
- up to 1.3.9.6
- Fixed in:
- 1.3.9.6
- Disclosed:
- Mar 9, 2015
WPshop 2 – E-Commerce [wpshop] < 1.3.9.6
unknown
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code executi...
- Affected:
- up to 1.3.9.6
- Fixed in:
- 1.3.9.6
- Disclosed:
- Mar 9, 2015
WPshop 2 – E-Commerce [wpshop] < 1.3.9.6
unknown
The script 'includes/ajax.php' allows execution of various actions by anonymous users. The action name is provided in the 'elementCode' parameter. One of these actions is named 'ajaxUpload'. This function allows for upload of arbitrary files, due to lack of sanitation of user input.
- Affected:
- up to 1.3.9.6
- Fixed in:
- 1.3.9.6
WPshop 2 – E-Commerce [wpshop] >= 2.0.0 - <= 2.6.0 (unfixed)
unknown
- Affected:
- 2.0.0 – 2.6.0
- Fix:
- No patched version reported
CVE-2025-3852 on NVD →
WPshop 2 – E-Commerce [wpshop] >= 2.0.0 - <= 2.6.0 (unfixed)
unknown
- Affected:
- 2.0.0 – 2.6.0
- Fix:
- No patched version reported
CVE-2025-3853 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database