Extension WordPress
Vulnérabilités WPshop 2 – E-Commerce
Cette page rassemble les failles publiées pour WPshop 2 – E-Commerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPshop 2 – E-Commerce
5 fiches
shop <= 2.6.1 – Unauthenticated Local File Inclusion
The shop plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of…
*-2.6.1
Non indiqué
09/02/2026
WPshop 2 – E-Commerce 2.0.0 – 2.6.0 – Authenticated (Subscriber+) Privilege Escalation via Account Takeover
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to the plugin not properly validating a user's identity prior to updating their details…
2.0.0-2.6.0
2.6.1
06/05/2025
WPshop 2 – E-Commerce 2.0.0 – 2.6.0 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Key Generation
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.6.0 via the callback_generate_api_key() due to missing validation on a user controlled key. This makes it possible for authenticated…
2.0.0-2.6.0
2.6.1
06/05/2025
WP shop <= 2.6.0 – Cross-Site Request Forgery to Arbitrary File Upload
The WP shop plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…
*-2.6.0
Non indiqué
09/04/2025
WPshop 2 – E-Commerce < 1.3.9.6 – Arbitrary File Upload
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary…
[*, 1.3.9.6)
1.3.9.6
09/03/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.