ShopSite

ShopSite has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for ShopSite has a vendor fix available, so running the current release closes it.

All of these findings were reported by SOPROBRO. ShopSite is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all ShopSite vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2024-13510

ShopSite <= 1.5.10 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv1.5.12
0.0(0)
0/100
Last Updated
2026-08-13 (1mo ago)
Active Installs
50+
Downloads
5,716
Requires WP
3.2.0+
Requires PHP
0+
Tested up to
WP 7.1
Created
2012-03-05 (15y ago)

The plugin integrates ShopSite shopping cart functionality with WordPress blogs. If you don’t have a ShopSite cart you can get a free Express store (http://saas.shopsite.com/express). After installing the plugin a merchant will be able to select ShopSite products directly from WordPress admin console and add them to her blog. The visitors of that blog will be able to add products to cart right on the blog, after which they are redirected to the merchant’s ShopSite store to check out. Requires ShopSite v11 SP2 or greater. Usage: There will be new button when adding a new post to the blog, with ShopSite’s “SS” on it. Clicking it will bring out a product search form where you can select products from your ShopSite’s store database to insert into the post. Note: Since WordPress switched their default editor in v5.x, the &#8216;Classic Editor Plugin’ is required. In WordPress go to Settings > Writing and change “Default editor for all users” to Classic.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C