WP Quick Shop
WP Quick Shop has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for WP Quick Shop has a vendor fix available, so running the current release closes it.
All of these findings were reported by thiennv. WP Quick Shop is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-54344WP Quick Shop <= 1.3.1 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

WP Quick Shop
Author
Fahad Mahmood
Author: Fahad Mahmood Project URI: http://androidbubble.com/blog/wordpress/plugins/wp-quick-shop Free Version: http://demo.androidbubble.com/wp-quick-shop Premium Version: http://demo.ibulb.work/wp-quick-shop License: GPL 3. See License below for copyright jots and titles. WP Quick Shop is a WooCommerce compatible plugin which enables you to setup a one-page shop for items to sell in bulk. You can add notes for each order item with custom field. WP Quick Shop can be implemented with just a shortcode. Create a page and paste shortcode. On Quick Shop page you can set quantity of items and use add to cart feature instantly. Every item is provided with a button to buy that item individually. Custom field will be saved with order details. Select Custom Field tab and enabled it. You can set custom field type like textarea, text and number. Column heading, field placeholder, tooltip and max length of field can be managed as well. Some styles are available for free and you can add your custom styles as well. Bootstrap is a premium feature as it will involve some complications with your theme templates and you might will require support from us later. Quick Implementation: Important! Visit my blog and suggest good features which you want to see in this plugin. License This WordPress Plugin is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or any later version. This free software is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this software. If not, see http://www.gnu.org/licenses/gpl-2.0.html.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C