First published: Thu Sep 09 2021(Updated: )
The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=1.2 |
Uninstall plugin from WordPress site.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38340 is classified as a medium severity vulnerability due to its potential for reflected Cross-Site Scripting.
To fix CVE-2021-38340, update the WordPress Simple Shop plugin to version 1.3 or later.
CVE-2021-38340 allows attackers to execute reflected Cross-Site Scripting attacks using the update_row parameter.
CVE-2021-38340 affects all versions of the WordPress Simple Shop plugin up to and including version 1.2.
The vulnerability for CVE-2021-38340 can be found in the ~/includes/add_product.php file, specifically involving the update_row parameter.