Description
WordPress Plugin WP e-Commerce-Store Toolkit is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin WP e-Commerce-Store Toolkit version 2.0.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.2 or latest
References
http://www.pritect.net/blog/visser-labs-wordpress-plugins-multiple-vulnerabilities
https://wordpress.org/plugins/wp-e-commerce-store-toolkit/changelog/
Related Vulnerabilities
MediaWiki Other Vulnerability (CVE-2004-2185)
WordPress Plugin Sermon Browser Cross-Site Scripting and SQL Injection Vulnerabilities (0.43)
WordPress Plugin Photoracer Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (1.0)
WordPress Plugin Advanced Custom Fields (ACF) 'acf_abspath' Parameter Remote File Include (3.5.1)