Description
WordPress Plugin eShop is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of the affected webserver process; this may result in total compromise of the web server. WordPress Plugin eShop version 6.3.11 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly validated or disable the plugin until a fix is available
References
https://www.htbridge.com/advisory/HTB23255
http://seclists.org/bugtraq/2015/May/34
http://cxsecurity.com/issue/WLB-2015050030
http://packetstormsecurity.com/files/131783/WordPress-eShop-6.3.11-Code-Execution.html
Related Vulnerabilities
WordPress Plugin Video.js-HTML5 Video Player for Wordpress Cross-Site Scripting (4.5.0)
Drupal Core 8.5.x Remote Code Execution (8.5.0 - 8.5.2)
WordPress Plugin YITH Maintenance Mode Multiple Cross-Site Scripting Vulnerabilities (1.3.8)
WordPress Plugin Add Any Extension to Pages Cross-Site Scripting (1.3)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-7983)