Extension WordPress
Vulnérabilités WP Marketplace – Complete Shopping Cart / eCommerce Solution
Cette page rassemble les failles publiées pour WP Marketplace – Complete Shopping Cart / eCommerce Solution, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Marketplace – Complete Shopping Cart / eCommerce Solution
3 fiches
Marketplace <= 2.4.0 – Path Traversal
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.
[*, 2.4.1)
2.4.1
21/03/2015
WP Marketplace – Complete Shopping Cart / eCommerce Solution <= 2.4.0 – Arbitrary File Download
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.
[*, 2.4.1)
2.4.1
21/03/2015
WP Marketplace – Complete Shopping Cart / eCommerce Solution <= 1.2.1 – Arbitrary File Upload
The WP Marketplace – Complete Shopping Cart / eCommerce Solution plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify/check.php and uploadify/uploadify.php files in versions up to, and including, 1.2.1.…
[*, 1.2.2)
1.2.2
08/04/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.