2 results (0.009 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

Unrestricted Upload of File with Dangerous Type vulnerability in Zendrop Zendrop – Global Dropshipping.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0. Carga sin restricciones de archivos con vulnerabilidad de tipo peligroso en Zendrop Zendrop – Global Dropshipping. Este problema afecta a Zendrop – Global Dropshipping: desde n/a hasta 1.0.0. The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.0.0. This makes it possible for attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. • https://patchstack.com/database/vulnerability/zendrop-dropshipping-and-fulfillment/wordpress-zendrop-global-dropshipping-plugin-1-0-0-arbitrary-file-upload?_s_id=cve • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0. Neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando SQL ('Inyección SQL') en Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment permite la inyección SQL. Este problema afecta a Zendrop – Global Dropshipping: desde n/a hasta 1.0.0 . The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to generic SQL Injection via the setMetaData function in versions up to, and including, 1.0.0 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. • https://patchstack.com/database/vulnerability/zendrop-dropshipping-and-fulfillment/wordpress-zendrop-global-dropshipping-plugin-1-0-0-arbitrary-code-execution?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •