plugin

Zingiri Web Shop Vulnerabilities

2 known security issues reported for the Zingiri Web Shop WordPress plugin. Most recent disclosed Apr 26, 2012.

1 critical 1 medium

Running Zingiri Web Shop on your site? Check whether your installed version is affected.

Scan your site free

Zingiri Web Shop Plugin <= 2.4.1 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in zing.inc.php or (2) notes parameter in fws/pages-front/onecheckout.php.

CVSS:
6.1
Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Apr 26, 2012

CVE-2012-6506 on NVD →

Zingiri Web Shop < 2.4.0 - Multiple Vulnerabilities

critical

The Zingiri Web Shop plugin for WordPress has multiple vulnerabilities in versions up to, and including, 2.3.7. This is due to the inclusion of timthumb.php, along with several cross-site scripting and SQL injection vulnerabilities. This makes it possible for unauthenticated attackers to access and altar data, and crea...

CVSS:
9.8
Affected:
up to 2.4.0
Fixed in:
2.4.0
Disclosed:
Apr 18, 2012

CVE-2012-4033 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database