WPshop 2 – E-Commerce
WPshop 2 – E-Commerce has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; 3 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 8.2, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2025 was the busiest year with 3 disclosures.
The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (20%). Other recurring categories include Cross-Site Request Forgery (CSRF), Improper Privilege Management.
3 of the records (60%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2025.
4 independent researchers contributed these findings, most of them (2) reported by kr0d. WPshop 2 – E-Commerce is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-32576WP shop <= 2.6.0 - Cross-Site Request Forgery to Arbitrary File Upload
Read the full analysisVulnerability Records

WPshop 2 – E-Commerce
Author
Agence web Eoxia - Montpellier
Simple and powerfull ECommerce plugin for WordPress WPShop 2 Turn your WordPress into e-commerce Simple, fast, efficient it will transform your WordPress into an internet sales site with Stripe, Paypal wpshop.fr Natively connect to your Dolibarr ERP, you just have to have coffee…[dolibarr.com](https://www.dolibarr.com/ Nos “french plugins” Developed in France, we can provide support and production of additional modules for bank payments. Stripe and Paypal are included. French documentation https://wpshop.fr/documentation/ Nos thèmes “ready for eCommerce” WPshop vous propose également des thèmes wordpress eCommerce optimisés et web responsives pour tablettes et mobiles. Contactez l’auteur technique@eoxia.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C