Description
Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows Upload a Web Shell to a Web Server.This issue affects WP shop: from n/a through <= 2.6.1.
Published: 2025-04-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery that permits an attacker to upload an arbitrary file to the web server. If a malicious file such as a web shell is uploaded, the attacker can gain remote code execution. The CVSS score of 9.6 reflects the high severity of the flaw, and the weakness is identified as CWE‑352.

Affected Systems

The affected product is the WP shop plugin from Agence web Eoxia – Montpellier. All versions from the earliest release through 2.6.1 are vulnerable, including the latest 2.6.1 release.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low prevalence of known exploitation at this time. Nevertheless, the high CVSS score indicates a critical risk. The likely attack scenario involves a malicious site sending a crafted request that exploits the missing CSRF protection when an authenticated user (ideally a privileged user or administrator) visits the site, thereby uploading a malicious payload that can be executed by the server.

Generated by OpenCVE AI on April 30, 2026 at 23:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable the file upload feature in WP shop or restrict it to trusted admins until a patch is applied.
  • Update the WP shop plugin to version 2.6.2 or later (or the latest release) to remove the CSRF flaw.
  • If an update is unavailable, augment security by applying a CSRF‑protection plugin that adds unique request tokens or by configuring the site to forbid uploads from untrusted users.

Generated by OpenCVE AI on April 30, 2026 at 23:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10590 Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop allows Upload a Web Shell to a Web Server. This issue affects WP shop: from n/a through 2.6.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop allows Upload a Web Shell to a Web Server. This issue affects WP shop: from n/a through 2.6.0. Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows Upload a Web Shell to a Web Server.This issue affects WP shop: from n/a through <= 2.6.1.
Title WordPress WP shop plugin <= 2.6.0 - CSRF to Arbitrary File Upload vulnerability WordPress WP shop plugin <= 2.6.1 - CSRF to Arbitrary File Upload vulnerability
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 09 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop allows Upload a Web Shell to a Web Server. This issue affects WP shop: from n/a through 2.6.0.
Title WordPress WP shop plugin <= 2.6.0 - CSRF to Arbitrary File Upload vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:24.337Z

Reserved: 2025-04-09T11:20:15.874Z

Link: CVE-2025-32576

cve-icon Vulnrichment

Updated: 2025-04-09T17:40:27.812Z

cve-icon NVD

Status : Deferred

Published: 2025-04-09T17:15:46.643

Modified: 2026-04-23T15:29:08.400

Link: CVE-2025-32576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T00:00:05Z

Weaknesses