The WP e-Commerce plug-in for WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Credit:
The information has been provided by Alexandr Polyakov
Vulnerable Systems:
* WP e-Commerce 3.8.7.6 and prior
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.A vulnerability has been reported in the WP e-Commerce plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.Certain unspecified input is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.