The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to disconnect the SimpleShop.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16996 | The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to disconnect the SimpleShop. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redbit Sro
Redbit Sro simple Shop |
|
| CPEs | cpe:2.3:a:redbit_sro:simple_shop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Redbit Sro
Redbit Sro simple Shop |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T18:33:25.170Z
Reserved: 2024-02-05T15:42:50.346Z
Link: CVE-2024-1229
Updated: 2024-08-01T18:33:25.170Z
Status : Awaiting Analysis
Published: 2024-05-14T14:45:42.160
Modified: 2024-11-21T08:50:06.520
Link: CVE-2024-1229
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:15:44Z
Weaknesses
No weakness.
EUVD