Cross-Site Request Forgery and Cross-Site Scripting in eshop Plugin for WordPress
CVE-2015-9413
What is CVE-2015-9413?
The eshop plugin for WordPress, versions up to 6.3.13, is vulnerable to Cross-Site Request Forgery (CSRF) attacks, which can allow unauthorized actions to be taken on behalf of authenticated users. Specifically, the vulnerability is exploited through the 'title' parameter of the 'wp-admin/admin.php?page=eshop-downloads.php' endpoint, enabling attackers to inject malicious scripts (XSS) that execute in the context of the user’s session. This can lead to significant security risks, including data theft and unauthorized access to sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved