Cross-Site Scripting
9 records56.3%First: 2023. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 16 vulnerability records associated with Ebook Store, published between 2023 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2023 | 3 | |
| 2024 | 4 | |
| 2025 | 6 | |
| 2026 | 3 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 6.3% |
| Medium | 15 | 93.8% |
First: 2023. Latest: 2025.
First: 2023. Latest: 2026.
First: 2024. Latest: 2026.
First: 2025. Latest: 2025.
First: 2025. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.205.80145.80155.80135.80095.80105.80025.78Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-6.19 | Ebook Store <= 6.19 - Unauthenticated Information Exposure | July 23, 2026 | 6.20 | Medium |
*-6.19 | Ebook Store <= 6.19 - Missing Authorization | July 22, 2026 | 6.20 | Medium |
*-6.19 | Ebook Store <= 6.19 - Missing Authorization | July 22, 2026 | 6.20 | Medium |
*-5.8013 | Ebook Store <= 5.8013 - Cross-Site Request Forgery | July 30, 2025 | 5.8014 | Medium |
*-5.8014 | Ebook Store <= 5.8014 - Reflected Cross-Site Scripting | July 26, 2025 | 5.8015 | Medium |
*-5.8012 | Ebook Store <= 5.8012 - Unauthenticated Arbitrary File Upload | July 23, 2025 | 5.8013 | Critical |
*-5.8012 | Ebook Store <= 5.8012 - Authenticated (Administrator+) Stored Cross-Site Scripting via Order Details | July 21, 2025 | 5.8013 | Medium |
*-5.8008 | Ebook Store <= 5.8008 - Authenticated (Administrator+) Stored Cross-Site Scripting | June 12, 2025 | 5.8009 | Medium |
*-5.8009 | Ebook Store <= 5.8009 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 7, 2025 | 5.8010 | Medium |
*-5.8001 | Ebook Store <= 5.8001 - Reflected Cross-Site Scripting | December 20, 2024 | 5.8002 | Medium |
*-5.8001 | Ebook Store <= 5.8001 - Reflected Cross-Site Scripting via 'step' | December 20, 2024 | 5.8002 | Medium |
*-5.8001 | Ebook Store <= 5.8001 - Unauthenticated Full Path Disclosure | August 1, 2024 | 5.8002 | Medium |
*-5.8001 | Ebook Store <= 5.8001 - Authenticated (Administrator+) Stored Cross-Site Scripting | March 1, 2024 | 5.8002 | Medium |
*-5.8009 | Ebook Store <= 5.8009 - Reflected Cross-Site Scripting | October 9, 2023 | 5.8010 | Medium |
*-5.775 | Ebook Store <= 5.775 - Missing Authorization via ebook_store_export_orders | April 19, 2023 | 5.78 | Medium |
[*, 5.78) | Ebook Store < 5.78 - Authenticated (Administrator+) Stored Cross-Site Scripting | April 19, 2023 | 5.78 | Medium |
Selected source records
Published: July 23, 2026
Published: July 22, 2026
Published: July 22, 2026
Published: July 30, 2025
Published: July 26, 2025
Published: July 23, 2025
Published: July 21, 2025
Published: June 12, 2025
Published: July 23, 2025
Published: April 19, 2023
Published: May 7, 2025
Published: December 20, 2024
Published: December 20, 2024
Published: July 26, 2025
Published: October 9, 2023
Published: July 22, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.