Description
WordPress Plugin Zingiri Web Shop is prone to multiple SQL injection and cross-site scripting vulnerabilities. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Zingiri Web Shop version 2.3.5 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
Jenkins Improper Input Validation Vulnerability (CVE-2018-1999002)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-7133)
Pym.js Embeds Cross-Site Scripting (1.3.2)
Squid Improper Input Validation Vulnerability (CVE-2020-8517)
Form Maker by 10Web-Mobile-Friendly Drag & Drop Contact Form Builder Cross-Site Scripting (1.13.39)