Description
WordPress Plugin Shoppable Images is prone to multiple vulnerabilities, including PHP object injection and cross-site request forgery vulnerabilities. A successful exploit may allow an attacker to execute arbitrary PHP code within the context of the affected webserver process or to perform certain administrative actions; other attacks are also possible. WordPress Plugin Shoppable Images version 1.0.0 is vulnerable.
Remediation
Update to plugin version 1.0.1 or latest
References
Related Vulnerabilities
MySQL CVE-2013-0384 Vulnerability (CVE-2013-0384)
WordPress Plugin BuddyPress Cross-Site Request Forgery (2.9.0)
WordPress Plugin Name Directory Cross-Site Request Forgery (1.17.4)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-46148)
Apache HTTP Server CVE-2019-0190 Vulnerability (CVE-2019-0190)