References https://nvd.nist.gov/vuln/detail/CVE-2015-10135 https://www.cve.org/CVERecord?id=CVE-2015-10135 https://github.com/advisories/GHSA-943m-x5xx-45qh https://cve.imfht.com/detail/CVE-2015-10135?lang=en https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpshop/wpshop-2-e-commerce-1396-arbitrary-file-upload https://patchstack.com/database/wordpress/plugin/wpshop/vulnerability/wordpress-wp-shop-plugin-1-3-9-5-arbitrary-file-upload https://www.rapid7.com/db/modules/exploit/unix/webapp/wp_wpshop_ecommerce_file_upload/ https://cert.kenet.or.ke/cve-2015-10135-wordpress-wpshop-file-upload-vulnerability https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2015-10135 https://support.alertlogic.com/hc/en-us/articles/360000092383-WordPress-WPshop-eCommerce-Arbitrary-File-Upload-Vulnerability
Related VulnerabilitiesPoCCVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL InjectionPoCCVE-2026-11387: SMS Alert – SMS & OTP for WooCommerce - Privilege EscalationPoCCVE-2026-71362: Adobe Commerce/Magento - Customer Session Identity SwitchPoCCVE-2026-27542: WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Unauthenticated Privilege EscalationPoCCVE-2026-3891: Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File UploadStripe Payment Plugin for WooCommerce /wc-api/WT_Stripe/ SQL 注入漏洞(CVE-2024-0705)WordPress TI WooCommerce Wishlist /wp-json/wc/v3/wishlist/get_products SQL 注入漏洞(CVE-2024-43917)PoCCVE-2025-13339: Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File ReadPoCCVE-2025-13773: WordPress Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Remote Code ExecutionPoCCVE-2026-10580: Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account TakeoverPoCCVE-2026-49777: WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCEWordPress WooCommerce OrderConvo 插件 /wp-json/wooconvo/v1/download-file 文件读取漏洞(CVE-2025-10162)PoCCVE-2025-47577: TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Upload