High 7.5 Unfixed
2026-02-20≤ 2.6.1
CVE-2025-69383
Minimum safe version
3.4.3.19
Update to 3.4.3.19 or later to address 6 fixable vulnerabilities
CVE-2025-69383
CVE-2015-10135
WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Key Generation
WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover
WordPress WP shop plugin <= 2.6.1 - CSRF to Arbitrary File Upload vulnerability
Wpshop - eCommerce <= 1.3.9.5 - Arbitrary File Upload
WPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File Upload
WordPress WP shop Plugin <= 1.3.9.5 - Arbitrary File Upload
WordPress Shop Plugin <= 3.4.3.15 - Blind SQL Injection
WordPress Shop Plugin <= 3.4.3.18 - Multiple Vulnerabilities