← WordPress Vulnerabilities
WordPress security by component

shopp_upload_file AJAX action of the Shopp

shopp_upload_file AJAX action of the Shopp provides an AJAX file upload action for the Shopp ecommerce plugin.

shopp_upload_file AJAX action of the Shopp (shopp) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 13, 2021; the highest published CVSS base score is 9.8.

Plugin slug: shopp

CVE-2021-24493: shopp_upload_file AJAX action of the Shopp: A security weakness

shopp_upload_file AJAX action of the Shopp is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedSep 13, 2021
Safe version guidanceSee mitigation notes
Published vulnerabilities for shopp
Safe version
Sep 13, 2021 CVE-2021-24493
shopp_upload_file AJAX action of the Shopp: A security weakness
shopp_upload_file AJAX action of the Shopp is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD9.8