← Back

CVE-2019-25214

nvd nist
Published: Oct 16, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to call the endpoints and perform unauthorized actions such as updating the plugin's settings and injecting malicious scripts.

Affected (1)

Products: Wpshop: Shopwp
1 product
Shopwp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.0.4

Timeline

No history available yet.