Vulnerabilities
Vulnerable Software
Eshop Project:  >> Eshop  >> 2.12.3  Security Vulnerabilities
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-09-26
The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-07-21


Contact Us

Shodan ® - All rights reserved