Zao's vulnerability profile is centered on its WP eCommerce plugin for WordPress, a widely deployed shopping-cart component across small and medium-sized online retailers. The durable signal reflects access-control weaknesses, particularly missing authorization checks, which are characteristic of plugin-layer functionality that directly extends WordPress's permission model. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zao over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1516MEDIUM The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions | Feb 28, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zao.
Media articles that mention a CVE ID that affects a product developed by Zao — matched by CVE ID, not by vendor name.