7.5
CVSSv3

CVE-2015-5468

Published: 23/05/2017 Updated: 01/06/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin prior to 2.6 for WordPress allows remote malicious users to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php.

Vulnerable Product Search on Vulmon Subscribe to Product

wpshopstyling wp e-commerce shop styling

Exploits

Title: Remote file download vulnerability in wordpress plugin wp-ecommerce-shop-styling v25 Author: Larry W Cashdollar, @_larry0 Date: 2015-07-05 Download Site: wordpressorg/plugins/wp-ecommerce-shop-styling Vendor: profileswordpressorg/haet/ Vendor Notified: 2015-07-05, fixed in version 26 Vendor Contact: wpshopstylin ...