Description
WordPress Plugin Zingiri Web Shop is prone to multiple SQL injection and cross-site scripting vulnerabilities. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Zingiri Web Shop version 2.3.5 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability (CVE-2020-36155)
WordPress Plugin WordPress Popular Posts TimThumb Arbitrary File Upload (2.1.4)
WordPress Plugin Front End Upload 'upload.php' Arbitrary File Upload (0.5.3)
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4226)