Simple Shopping Cart <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsc_display_product' Shortcode
Simple Shopping Cart
Minimum safe version
5.2.5
Update to 5.2.5 or later to address 11 fixable vulnerabilities
WordPress Simple PayPal Shopping Cart <= 5.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference via 'quantity'
WordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference
WordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Information Exposure via file_url Parameter
WordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Product Price Manipulation
CVE-2024-12622
WordPress Simple Shopping Cart Plugin <= 4.7.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-1431
CVE-2022-4672
WordPress Simple PayPal Shopping Cart < 3.6 - Cross-Site Request Forgery