High 7.1
2025-01-27< 1.2.0
CVE-2025-24626
Minimum safe version
1.2.0
Update to 1.2.0 or later to address 8 fixable vulnerabilities
CVE-2025-24626
WordPress Music Store Plugin <= 1.1.13 is vulnerable to SQL Injection
Music Store - WordPress eCommerce <= 1.1.13 - Authenticated (Admin+) SQL Injection
Music Store <= 1.0.14 - Referer Header Open Redirect
Music Store – WordPress eCommerce < 1.0.15 - Open Redirect
WordPress Music Store Plugin <= 1.0.14 - Open Redirection
WordPress Music Store Plugin <= 1.0.41 - Cross Site Scripting (XSS)
CVE-2016-10992