CVE-2012-3576: Critical severity wpstorecart vulnerability
Published Jun 16, 2012
·Updated
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/wpstorecart.
Affected Software
99 affected components
Jquindlen Wpstorecart<=2.5.29
Jquindlen Wpstorecart=0.62
Jquindlen Wpstorecart=1.0.0
Jquindlen Wpstorecart=2.0.0
Jquindlen Wpstorecart=2.0.1
Jquindlen Wpstorecart=2.0.2
Jquindlen Wpstorecart=2.0.3
Jquindlen Wpstorecart=2.0.4
Jquindlen Wpstorecart=2.0.5
Jquindlen Wpstorecart=2.0.6
Jquindlen Wpstorecart=2.0.7
Jquindlen Wpstorecart=2.0.8
Jquindlen Wpstorecart=2.0.9
Jquindlen Wpstorecart=2.0.10
Jquindlen Wpstorecart=2.0.11
Jquindlen Wpstorecart=2.0.12
Jquindlen Wpstorecart=2.0.13
Jquindlen Wpstorecart=2.1.0
Jquindlen Wpstorecart=2.1.1
Jquindlen Wpstorecart=2.1.2
Jquindlen Wpstorecart=2.1.3
Jquindlen Wpstorecart=2.1.4
Jquindlen Wpstorecart=2.1.5
Jquindlen Wpstorecart=2.1.6
Jquindlen Wpstorecart=2.1.7
Jquindlen Wpstorecart=2.1.8
Jquindlen Wpstorecart=2.2.0
Jquindlen Wpstorecart=2.2.1
Jquindlen Wpstorecart=2.2.2
Jquindlen Wpstorecart=2.2.3
Jquindlen Wpstorecart=2.2.4
Jquindlen Wpstorecart=2.2.5
Jquindlen Wpstorecart=2.2.6
Jquindlen Wpstorecart=2.2.7
Jquindlen Wpstorecart=2.2.8
Jquindlen Wpstorecart=2.2.9
Jquindlen Wpstorecart=2.3.0
Jquindlen Wpstorecart=2.3.1
Jquindlen Wpstorecart=2.3.2
Jquindlen Wpstorecart=2.3.3
Jquindlen Wpstorecart=2.3.4
Jquindlen Wpstorecart=2.3.5
Jquindlen Wpstorecart=2.3.6
Jquindlen Wpstorecart=2.3.7
Jquindlen Wpstorecart=2.3.8
Jquindlen Wpstorecart=2.3.9
Jquindlen Wpstorecart=2.3.10
Jquindlen Wpstorecart=2.3.11
Jquindlen Wpstorecart=2.3.12
Jquindlen Wpstorecart=2.3.13
Jquindlen Wpstorecart=2.3.14
Jquindlen Wpstorecart=2.3.15
Jquindlen Wpstorecart=2.3.16
Jquindlen Wpstorecart=2.3.17
Jquindlen Wpstorecart=2.4.0
Jquindlen Wpstorecart=2.4.1
Jquindlen Wpstorecart=2.4.2
Jquindlen Wpstorecart=2.4.3
Jquindlen Wpstorecart=2.4.4
Jquindlen Wpstorecart=2.4.5
Jquindlen Wpstorecart=2.4.6
Jquindlen Wpstorecart=2.4.7
Jquindlen Wpstorecart=2.4.8
Jquindlen Wpstorecart=2.4.9
Jquindlen Wpstorecart=2.4.10
Jquindlen Wpstorecart=2.4.11
Jquindlen Wpstorecart=2.4.12
Jquindlen Wpstorecart=2.4.13
Jquindlen Wpstorecart=2.4.14
Jquindlen Wpstorecart=2.5.0
Jquindlen Wpstorecart=2.5.1
Jquindlen Wpstorecart=2.5.2
Jquindlen Wpstorecart=2.5.3
Jquindlen Wpstorecart=2.5.4
Jquindlen Wpstorecart=2.5.5
Jquindlen Wpstorecart=2.5.6
Jquindlen Wpstorecart=2.5.7
Jquindlen Wpstorecart=2.5.8
Jquindlen Wpstorecart=2.5.9
Jquindlen Wpstorecart=2.5.10
Jquindlen Wpstorecart=2.5.11
Jquindlen Wpstorecart=2.5.12
Jquindlen Wpstorecart=2.5.13
Jquindlen Wpstorecart=2.5.14
Jquindlen Wpstorecart=2.5.15
Jquindlen Wpstorecart=2.5.16
Jquindlen Wpstorecart=2.5.17
Jquindlen Wpstorecart=2.5.18
Jquindlen Wpstorecart=2.5.19
Jquindlen Wpstorecart=2.5.20
Jquindlen Wpstorecart=2.5.21
Jquindlen Wpstorecart=2.5.22
Jquindlen Wpstorecart=2.5.23
Jquindlen Wpstorecart=2.5.24
Jquindlen Wpstorecart=2.5.25
Jquindlen Wpstorecart=2.5.26
Jquindlen Wpstorecart=2.5.27
Jquindlen Wpstorecart=2.5.28
WordPress WordPress
Event History
Jun 16, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3576?
CVE-2012-3576 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2012-3576?
To fix CVE-2012-3576, update the wpStoreCart plugin to version 2.5.30 or later.
3
What types of files can be uploaded in CVE-2012-3576?
CVE-2012-3576 allows attackers to upload files with executable extensions.
4
What is the impact of exploiting CVE-2012-3576?
Exploitation of CVE-2012-3576 can lead to arbitrary code execution on the server.
5
Which versions of wpStoreCart are affected by CVE-2012-3576?
CVE-2012-3576 affects all versions of the wpStoreCart plugin before 2.5.30.