← All CVEs

CVE-2012-3576

high · 10

Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/wpstorecart.

10
CVSS
18.4%
EPSS (exploit prob.)
97th
EPSS percentile
2012-06-16
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
jquindlenwpstorecart<= 2.5.29
jquindlenwpstorecart0.62
jquindlenwpstorecart1.0.0
jquindlenwpstorecart2.0.0
jquindlenwpstorecart2.0.1
jquindlenwpstorecart2.0.2
jquindlenwpstorecart2.0.3
jquindlenwpstorecart2.0.4
jquindlenwpstorecart2.0.5
jquindlenwpstorecart2.0.6
jquindlenwpstorecart2.0.7
jquindlenwpstorecart2.0.8
jquindlenwpstorecart2.0.9
jquindlenwpstorecart2.0.10
jquindlenwpstorecart2.0.11
jquindlenwpstorecart2.0.12
jquindlenwpstorecart2.0.13
jquindlenwpstorecart2.1.0
jquindlenwpstorecart2.1.1
jquindlenwpstorecart2.1.2
jquindlenwpstorecart2.1.3
jquindlenwpstorecart2.1.4
jquindlenwpstorecart2.1.5
jquindlenwpstorecart2.1.6
jquindlenwpstorecart2.1.7
jquindlenwpstorecart2.1.8
jquindlenwpstorecart2.2.0
jquindlenwpstorecart2.2.1
jquindlenwpstorecart2.2.2
jquindlenwpstorecart2.2.3
jquindlenwpstorecart2.2.4
jquindlenwpstorecart2.2.5
jquindlenwpstorecart2.2.6
jquindlenwpstorecart2.2.7
jquindlenwpstorecart2.2.8
jquindlenwpstorecart2.2.9
jquindlenwpstorecart2.3.0
jquindlenwpstorecart2.3.1
jquindlenwpstorecart2.3.2
jquindlenwpstorecart2.3.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-3576