Description
WordPress Plugin Zingiri Web Shop is prone to multiple SQL injection and cross-site scripting vulnerabilities. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Zingiri Web Shop version 2.3.5 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-6624)
ZenCart Improper Authentication Vulnerability (CVE-2009-2255)
WordPress Plugin Ginger-EU Cookie Law Multiple Vulnerabilities (4.1.3)
WordPress Plugin Batch Cat Security Bypass (0.3)
WordPress Plugin CF7 Invisible reCAPTCHA Cross-Site Scripting (1.3.1)