Zingiri Web Shop Plugin <= 2.4.1 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in zing.inc.php or (2) notes parameter in fws/pages-front/onecheckout.php.
- CVSS:
- 6.1
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Apr 26, 2012
CVE-2012-6506 on NVD →
Zingiri Web Shop < 2.4.0 - Multiple Vulnerabilities
critical
The Zingiri Web Shop plugin for WordPress has multiple vulnerabilities in versions up to, and including, 2.3.7. This is due to the inclusion of timthumb.php, along with several cross-site scripting and SQL injection vulnerabilities. This makes it possible for unauthenticated attackers to access and altar data, and crea...
- CVSS:
- 9.8
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.0
- Disclosed:
- Apr 18, 2012
CVE-2012-4033 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database