Input validation vulnerability in eMagicOne Store Manager for WooCommerce 1.2.5

A popular plugin for WordPress called eMagicOne Store Manager for WooCommerce has a security vulnerability that allows attackers to upload any type of file onto a website using the plugin. This could potentially lead to attackers being able to run their own code on the website’s server. This vulnerability can only be taken advantage of if the website’s default password is not changed or if the attacker is able to obtain the login credentials.

Detected in:

eMagicOne Store Manager for WooCommerce fixed vulnerable versions: >= * <= 1.2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.