← WordPress Vulnerabilities
WordPress security by component

shopp_upload_file AJAX action of the Shopp

shopp_upload_file AJAX action of the Shopp is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 13, 2021; the highest CVE/CNA score is 9.8.

Plugin slug: shopp

CVE-2021-24493: shopp_upload_file AJAX action of the Shopp: A security weakness

shopp_upload_file AJAX action of the Shopp is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedSep 13, 2021
Safe version guidanceSee mitigation notes
Safe version
Sep 13, 2021 CVE-2021-24493
shopp_upload_file AJAX action of the Shopp: A security weakness
shopp_upload_file AJAX action of the Shopp is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8