cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwpshopgermany-it-recht-kanzlei wpshopgermany-it-recht-kanzlei

Direction: ascending
Jun 07, 2024

wpShopGermany IT-RECHT KANZLEI # CVE-2023-37993

CVE, Research URL

CVE-2023-37993

Date
Jul 27, 2023
Research Description
Auth. Stored Cross-Site Scripting (XSS) vulnerability in maennchen1.De wpShopGermany IT-RECHT KANZLEI plugin <= 1.7 versions.
Affected versions
max 1.8.
Status
vulnerable
Apr 03, 2025

wpShopGermany IT-RECHT KANZLEI # CVE-2025-30804

CVE, Research URL

CVE-2025-30804

Date
Mar 27, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in maennchen1.de wpShopGermany IT-RECHT KANZLEI wpshopgermany-it-recht-kanzlei allows Cross Site Request Forgery.This issue affects wpShopGermany IT-RECHT KANZLEI: from n/a through <= 2.0.
Affected versions
max 2.1.
Status
vulnerable
Sep 19, 2026

wpShopGermany IT-RECHT KANZLEI # CVE-2026-88795

CVE, Research URL

CVE-2026-88795

Date
Sep 17, 2026
Research Description
The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access it grants to write arbitrary files, leading to remote code execution.
Affected versions
max 2.4.
Status
vulnerable