Zendrop – Global Dropshipping [zendrop-dropshipping-and-fulfillment] < 1.0.1 (closed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Zendrop Zendrop – Global Dropshipping.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0.
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Dec 20, 2023
CVE-2023-25970 on NVD →
Zendrop – Global Dropshipping [zendrop-dropshipping-and-fulfillment] < 1.0.1 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0.
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Nov 3, 2023
CVE-2023-25960 on NVD →
Zendrop – Global Dropshipping <= 1.0.0 - SQL Injection in setMetaData
critical
The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to generic SQL Injection via the setMetaData function in versions up to, and including, 1.0.0 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthent...
- CVSS:
- 9.8
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.1
- Disclosed:
- Feb 24, 2023
CVE-2023-25960 on NVD →
Zendrop – Global Dropshipping <= 1.0.0 - Arbitrary File Upload
critical
The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.0.0. This makes it possible for attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- CVSS:
- 9.8
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.1
- Disclosed:
- Feb 24, 2023
CVE-2023-25970 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database