Vulnerability Description
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eshop Project | Eshop | <= 6.3.13 |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/files/133480/ExploitThird Party AdvisoryVDB Entry
- https://wordpress.org/plugins/eshop/#developersProductThird Party Advisory
- https://wpvulndb.com/vulnerabilities/8180ExploitThird Party Advisory
- https://packetstormsecurity.com/files/133480/ExploitThird Party AdvisoryVDB Entry
- https://wordpress.org/plugins/eshop/#developersProductThird Party Advisory
- https://wpvulndb.com/vulnerabilities/8180ExploitThird Party Advisory
FAQ
What is CVE-2015-9413?
CVE-2015-9413 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
How severe is CVE-2015-9413?
CVE-2015-9413 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-9413?
Check the references section above for vendor advisories and patch information. Affected products include: Eshop Project Eshop.