vendor:
Zingiri Web Shop Plugin
by:
Mehmet Ince
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Zingiri Web Shop Plugin
Affected Version From: <= 2.4.0
Affected Version To: 2.4.2002
Patch Exists: YES
Related CWE:
CPE: a:zingiri:zingiri_web_shop_plugin:2.4.0
Platforms Tested: Ubuntu 11.10 with Apache server on Firefox
2012
WordPress Zingiri Web Shop Plugin <= 2.4.2 Stored XSS
This exploit allows an attacker to execute arbitrary scripts in the context of the user's browser, potentially compromising their session or stealing sensitive information.
Mitigation:
The vulnerability was fixed in version 2.4.2 of the Zingiri Web Shop Plugin. Users are advised to update to the latest version to mitigate this issue.