WordPress Simple Ecommerce Shopping Cart Plugin <= 3.1.2 is vulnerable to Arbitrary File Upload

Low priority No impactful threat
<= 3.1.2Vulnerable version(s)
No official patch availablePatched version

Get the fastest vulnerability mitigation with Patchstack!

Get started

Risks

CVSS 6

Vulnerabilities like this one are used in mass-exploit campaigns. Attackers use these to attack thousands of websites at a time, regardless of traffic size or popularity. Learn more.

As immediate action, update the affected plugin. If you're unable to do so, ask your hosting provider or web developer for help.

6

Arbitrary File Upload

This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website.

CVSS score is a way to evaluate and rank reported vulnerabilities in a standardized and repeatable way but which is not ideal for WordPress.

Solutions

This security issue has a low severity impact and is unlikely to be exploited.

Details

Have additional information or questions about this entry? Let us know.

Weekly WordPress security intelligence delivered to your inbox.