WordPress Simple Ecommerce Shopping Cart Plugin <= 3.1.2 is vulnerable to Arbitrary File Upload

Low priority No impactful threat
<= 3.1.2Vulnerable version(s)
No official patch availablePatched version

Get the fastest vulnerability mitigation with Patchstack!

Get started

Risks

CVSS 6

As immediate action, update the affected plugin. If you're unable to do so, ask your hosting provider or web developer for help.

6

Arbitrary File Upload

Attackers can upload malicious files to the server, which can be used to take it over.

CVSS score is a way to evaluate and rank reported vulnerabilities in a standardized and repeatable way but which is not ideal for WordPress.

Solutions

This security issue has a low severity impact and is unlikely to be exploited.

Details

Have additional information or questions about this entry? Let us know.

Weekly WordPress security intelligence delivered to your inbox.