plugin

Wpshop Vulnerabilities

15 known security issues reported for the Wpshop WordPress plugin. Most recent disclosed Feb 20, 2026.

1 critical 3 high 1 medium

Running Wpshop on your site? Check whether your installed version is affected.

Scan your site free

WPshop 2 &#8211; E-Commerce [wpshop] <= 2.6.1 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows PHP Local File Inclusion.This issue affects WP shop: from n/a through <= 2.6.1.

Affected:
up to 2.6.1
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-69383 on NVD →

shop <= 2.6.1 - Unauthenticated Local File Inclusion

high

The shop plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtai...

CVSS:
8.1
Affected:
up to 2.6.1
Fix:
No patched version reported
Disclosed:
Feb 9, 2026

CVE-2025-69383 on NVD →

WPshop 2 &#8211; E-Commerce [wpshop] < 1.3.9.6

unknown

[en] The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code ex...

Affected:
up to 1.3.9.6
Fixed in:
1.3.9.6
Disclosed:
Jul 19, 2025

CVE-2015-10135 on NVD →

WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover

high

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email & password through the update() function. This makes it possible for authen...

CVSS:
8.8
Affected:
2.0.0 – 2.6.0
Fixed in:
2.6.1
Disclosed:
May 6, 2025

CVE-2025-3852 on NVD →

WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Key Generation

medium

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.6.0 via the callback_generate_api_key() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create valid...

CVSS:
5.4
Affected:
2.0.0 – 2.6.0
Fixed in:
2.6.1
Disclosed:
May 6, 2025

CVE-2025-3853 on NVD →

WP shop <= 2.6.0 - Cross-Site Request Forgery to Arbitrary File Upload

high

The WP shop plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site admi...

CVSS:
8.8
Affected:
up to 2.6.0
Fix:
No patched version reported
Disclosed:
Apr 9, 2025

CVE-2025-32576 on NVD →

WPshop 2 &#8211; E-Commerce [wpshop] <= 2.6.0 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop allows Upload a Web Shell to a Web Server. This issue affects WP shop: from n/a through 2.6.0.

Affected:
up to 2.6.0
Fix:
No patched version reported
Disclosed:
Apr 9, 2025

CVE-2025-32576 on NVD →

WPshop 2 &#8211; E-Commerce [wpshop] < 3.4.3.19

unknown

This plugin is prone to cross site scripting and cross site request forgery vulnerabilities. Update the plugin.

Affected:
up to 3.4.3.19
Fixed in:
3.4.3.19
Disclosed:
Sep 17, 2015

WPshop 2 &#8211; E-Commerce [wpshop] < 3.4.3.16

unknown

This plugin is prone to an SQL injection via "wpshop_id" parameter. Update the plugin.

Affected:
up to 3.4.3.16
Fixed in:
3.4.3.16
Disclosed:
Jul 8, 2015

WPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File Upload

critical

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code executi...

CVSS:
9.8
Affected:
up to 1.3.9.6
Fixed in:
1.3.9.6
Disclosed:
Mar 9, 2015

CVE-2015-10135 on NVD →

WPshop 2 &#8211; E-Commerce [wpshop] < 1.3.9.6

unknown

This plugin is prone to an arbitrary file upload vulnerability during "ajaxUpload" action. Update the plugin.

Affected:
up to 1.3.9.6
Fixed in:
1.3.9.6
Disclosed:
Mar 9, 2015

WPshop 2 &#8211; E-Commerce [wpshop] < 1.3.9.6

unknown

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code executi...

Affected:
up to 1.3.9.6
Fixed in:
1.3.9.6
Disclosed:
Mar 9, 2015

WPshop 2 &#8211; E-Commerce [wpshop] < 1.3.9.6

unknown

The script &#039;includes/ajax.php&#039; allows execution of various actions by anonymous users. The action name is provided in the &#039;elementCode&#039; parameter. One of these actions is named &#039;ajaxUpload&#039;. This function allows for upload of arbitrary files, due to lack of sanitation of user input.

Affected:
up to 1.3.9.6
Fixed in:
1.3.9.6

WPshop 2 &#8211; E-Commerce [wpshop] >= 2.0.0 - <= 2.6.0 (unfixed)

unknown
Affected:
2.0.0 – 2.6.0
Fix:
No patched version reported

CVE-2025-3852 on NVD →

WPshop 2 &#8211; E-Commerce [wpshop] >= 2.0.0 - <= 2.6.0 (unfixed)

unknown
Affected:
2.0.0 – 2.6.0
Fix:
No patched version reported

CVE-2025-3853 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database