ShopSite
ShopSite has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for ShopSite has a vendor fix available, so running the current release closes it.
All of these findings were reported by SOPROBRO. ShopSite is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-13510ShopSite <= 1.5.10 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records
ShopSite
Author
ShopSite
The plugin integrates ShopSite shopping cart functionality with WordPress blogs. If you don’t have a ShopSite cart you can get a free Express store (http://saas.shopsite.com/express). After installing the plugin a merchant will be able to select ShopSite products directly from WordPress admin console and add them to her blog. The visitors of that blog will be able to add products to cart right on the blog, after which they are redirected to the merchant’s ShopSite store to check out. Requires ShopSite v11 SP2 or greater. Usage: There will be new button when adding a new post to the blog, with ShopSite’s “SS” on it. Clicking it will bring out a product search form where you can select products from your ShopSite’s store database to insert into the post. Note: Since WordPress switched their default editor in v5.x, the ‘Classic Editor Plugin’ is required. In WordPress go to Settings > Writing and change “Default editor for all users” to Classic.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C