VYPR
Vendor

Wp Ecommerce

Products
3
CVEs
15
Across products
15
Status
Private

Products

3

Recent CVEs

15
  • CVE-2024-1514CriFeb 28, 2024
    risk 0.64cvss 9.8epss 0.01

    The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2019-25141CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated…

  • CVE-2022-27357CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.03

    Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-42699CriDec 6, 2022
    risk 0.59cvss 9.1epss 0.01

    Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

  • CVE-2022-45829HigDec 6, 2022
    risk 0.57cvss 8.7epss 0.01

    Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.

  • CVE-2022-27435HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.

  • CVE-2020-35234HigDec 14, 2020
    risk 0.57cvss 7.5epss 0.65

    The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt)…

  • CVE-2022-3334HigOct 31, 2022
    risk 0.47cvss 7.2epss 0.01

    The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

  • CVE-2022-45833MedDec 6, 2022
    risk 0.44cvss 6.8epss 0.01

    Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

  • CVE-2024-35676MedJun 8, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through 1.7.

  • CVE-2017-7723MedApr 24, 2017
    risk 0.40cvss 6.1epss 0.01

    XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.

  • CVE-2022-27436MedApr 4, 2022
    risk 0.31cvss 4.8epss 0.01

    A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.

  • CVE-2024-3073LowJun 13, 2024
    risk 0.18cvss 2.7epss 0.00

    The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.3.0. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings.…

  • CVE-2006-1098Mar 9, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by…

  • CVE-2006-1096Mar 9, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this…