PT-2026-2636 · WordPress · Cp Image Store With Slideshow

·

CVE-2026-0684

·

Publicado

2026-01-13

·

Atualizado

2026-01-13

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CP Image Store with Slideshow plugin for WordPress versions up to and including 1.1.9
Description The CP Image Store with Slideshow plugin for WordPress contains a flaw where an authenticated attacker with Contributor-level access or higher can import arbitrary products via XML, provided the XML file has been previously uploaded to the server. This is due to a logic error in the permission check within the cpis admin init function.
Recommendations Update the CP Image Store with Slideshow plugin to a version later than 1.1.9.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-0684

Produtos afetados

Cp Image Store With Slideshow