Description
WordPress Plugin WP e-Commerce Shop Styling is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin WP e-Commerce Shop Styling version 2.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.6 or latest
References
http://www.vapidlabs.com/advisory.php?v=136
https://www.exploit-db.com/exploits/37530/
http://seclists.org/oss-sec/2015/q3/48
Related Vulnerabilities
WordPress 2.3 Cross-Site Scripting Vulnerability (2.3 - 2.3)
WordPress Plugin AccessPress Social Icons SQL Injection (1.8.0)
WordPress Plugin EmbedSocial-Social Media Feeds, Reviews and Galleries Cross-Site Scripting (1.1.27)
WordPress Plugin Catch Web Tools Security Bypass (2.6.6)
WordPress Plugin WordPress Download Manager Cross-Site Scripting (2.9.93)