CVE-2011-5104
Getshopped WP E-commerce < 3.8.7.1 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possibly earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_text parameter. NOTE: some of these details are obtained from third party information.
References (6)
Scores
EPSS
0.0043
EPSS Percentile
62.3%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
getshopped/wp_e-commerce
< 3.8.7.1
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
getshopped/wp_e-commerce
... and 35 more
Timeline
Published
Aug 23, 2012
Tracked Since
Feb 18, 2026