CVE-2015-10135

CRITICAL

WPshop 2 - E-Commerce < 1.3.9.6 - Unauthenticated Arbitrary File Upload via ajaxUpload Function

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-10135. PoCs published by g0blin, including Metasploit module exploits/unix/webapp/wp_wpshop_ecommerce_file_upload.

AI-analyzed exploit summary This Metasploit module exploits an arbitrary file upload vulnerability in the WordPress WPshop eCommerce plugin (versions 1.3.3.3 to 1.3.9.5), allowing remote code execution by uploading a malicious PHP file. The exploit leverages a multipart form data upload to bypass restrictions and execute the payload.

Description

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Exploits (1)

metasploit WORKING POC EXCELLENT
by g0blin · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_wpshop_ecommerce_file_upload.rb

This Metasploit module exploits an arbitrary file upload vulnerability in the WordPress WPshop eCommerce plugin (versions 1.3.3.3 to 1.3.9.5), allowing remote code execution by uploading a malicious PHP file. The exploit leverages a multipart form data upload to bypass restrictions and execute the payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress WPshop eCommerce plugin 1.3.3.3 to 1.3.9.5
No auth needed
Prerequisites: Target running vulnerable WPshop eCommerce plugin · Network access to the WordPress site
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.7778
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
eoxia/WPshop 2 – E-Commerce < 1.3.9.6
eoxia/wpshop_2 < 1.3.9.6
Published Jul 19, 2025
Tracked Since Feb 18, 2026