Real WP Shop Lite Ajax eCommerce Shopping Cart Security & Risk Analysis

wordpress.org/plugins/real-wp-shop-lite

Light, powerful, easy to use and theme WordPress ecommerce / shopping cart plugin that utilizes ajax for better user experience.

10 active installs v2.0.8 PHP + WP 3.0.1+ Updated Mar 12, 2016
adminattributesblog-catalogcatalogcatalogue
64
C · Use Caution
CVEs total1
Unpatched1
Last CVENov 12, 2024
Safety Verdict

Is Real WP Shop Lite Ajax eCommerce Shopping Cart Safe to Use in 2026?

Use With Caution

Score 64/100

Real WP Shop Lite Ajax eCommerce Shopping Cart has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Nov 12, 2024Updated 10yr ago
Risk Assessment

The security posture of real-wp-shop-lite v2.0.8 presents significant concerns, primarily due to a large number of unprotected AJAX handlers and a concerningly low rate of proper output escaping. While the plugin demonstrates some good practices like the use of prepared statements for SQL queries and the inclusion of nonce checks, these are overshadowed by critical weaknesses that expose the application to potential attacks. The presence of flows with unsanitized paths, especially those flagged as high severity in taint analysis, directly points to potential injection vulnerabilities.

The plugin's vulnerability history, including a recent medium-severity Cross-Site Scripting (XSS) vulnerability, further emphasizes the risks. The fact that this vulnerability remains unpatched is a critical indicator of ongoing security issues and a lack of timely remediation. While the plugin does not appear to rely on outdated bundled libraries, the combination of a broad, unprotected attack surface, insufficient output sanitization, and a history of unaddressed vulnerabilities creates a high-risk profile. Users should exercise extreme caution and prioritize updating to a version that addresses these identified weaknesses.

Key Concerns

  • Unprotected AJAX handlers
  • Low rate of proper output escaping
  • High severity taint flows
  • Unpatched CVE
  • Flows with unsanitized paths
  • No capability checks on entry points
Vulnerabilities
1 published

Real WP Shop Lite Ajax eCommerce Shopping Cart Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11140medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Real WP Shop Lite Ajax eCommerce Shopping Cart <= 2.0.8 - Authenticated (Administrator+) Stored Cross-Site Scripting

Nov 12, 2024Unpatched
Version History

Real WP Shop Lite Ajax eCommerce Shopping Cart Release Timeline

v2.0.8Current1 CVE
v2.0.71 CVE
v2.0.61 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 17, 2026

Real WP Shop Lite Ajax eCommerce Shopping Cart Code Analysis

Dangerous Functions
0
Raw SQL Queries
26
21 prepared
Unescaped Output
138
12 escaped
Nonce Checks
12
Capability Checks
0
File Operations
3
External Requests
1
Bundled Libraries
1

Bundled Libraries

jQuery

SQL Query Safety

45% prepared47 total queries

Output Escaping

8% escaped150 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

12 flows3 with unsanitized paths
vkrwps_get_search_prod (real-wp-shop-lite.php:1621)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
26 unprotected

Real WP Shop Lite Ajax eCommerce Shopping Cart Attack Surface

Entry Points33
Unprotected26

AJAX Handlers 26

authwp_ajax_DELETE_ORDER_ROWinc\pc\a_delete_order_row.php:3
authwp_ajax_EDIT_PRODinc\pc\a_edit_products.php:3
authwp_ajax_ORDERS_PAGINGinc\pc\a_orders_paging.php:3
authwp_ajax_UPDATE_ORDER_STATUSinc\pc\a_update_order_status.php:3
noprivwp_ajax_PROD_PAGINGreal-wp-shop-lite.php:189
authwp_ajax_PROD_PAGINGreal-wp-shop-lite.php:190
noprivwp_ajax_ADD_PRODreal-wp-shop-lite.php:553
authwp_ajax_ADD_PRODreal-wp-shop-lite.php:554
noprivwp_ajax_ADD_PROD_COreal-wp-shop-lite.php:605
authwp_ajax_ADD_PROD_COreal-wp-shop-lite.php:606
noprivwp_ajax_B2_CHECKOUTreal-wp-shop-lite.php:857
authwp_ajax_B2_CHECKOUTreal-wp-shop-lite.php:858
noprivwp_ajax_STEP2real-wp-shop-lite.php:880
authwp_ajax_STEP2real-wp-shop-lite.php:881
noprivwp_ajax_STEP3real-wp-shop-lite.php:968
authwp_ajax_STEP3real-wp-shop-lite.php:969
noprivwp_ajax_ADD_CUST_INFOreal-wp-shop-lite.php:1123
authwp_ajax_ADD_CUST_INFOreal-wp-shop-lite.php:1124
noprivwp_ajax_DO_SEARCHreal-wp-shop-lite.php:1558
authwp_ajax_DO_SEARCHreal-wp-shop-lite.php:1559
noprivwp_ajax_GET_SEARCH_PRODreal-wp-shop-lite.php:1619
authwp_ajax_GET_SEARCH_PRODreal-wp-shop-lite.php:1620
noprivwp_ajax_SHOW_CARTreal-wp-shop-lite.php:1701
authwp_ajax_SHOW_CARTreal-wp-shop-lite.php:1702
noprivwp_ajax_ADD_CUST_INFO_PAYPAL_IPNreal-wp-shop-lite.php:1737
authwp_ajax_ADD_CUST_INFO_PAYPAL_IPNreal-wp-shop-lite.php:1738

Shortcodes 7

[vkrwps_products] real-wp-shop-lite.php:55
[sstest] real-wp-shop-lite.php:288
[rwps_full_product] real-wp-shop-lite.php:300
[vkrwps_cart] real-wp-shop-lite.php:365
[vkrwps_checkout] real-wp-shop-lite.php:667
[rwps_search] real-wp-shop-lite.php:1544
[rwpsipn] real-wp-shop-lite.php:1739
WordPress Hooks 16
actionadmin_menuinc\get_pc.php:3
actionadmin_menuinc\get_pc.php:8
actionadmin_menuinc\get_pc.php:16
actionadmin_menuinc\get_pc.php:23
actionadmin_menuinc\get_pc.php:30
actionadmin_menuinc\get_pc.php:37
actionadmin_menuinc\get_pc.php:44
actionadmin_menuinc\get_pc.php:51
actionwp_enqueue_scriptsreal-wp-shop-lite.php:38
actionadmin_enqueue_scriptsreal-wp-shop-lite.php:47
filterthe_contentreal-wp-shop-lite.php:291
filterthe_contentreal-wp-shop-lite.php:292
actionwp_enqueue_scriptsreal-wp-shop-lite.php:1643
actionadmin_enqueue_scriptsreal-wp-shop-lite.php:1708
actionadmin_enqueue_scriptsreal-wp-shop-lite.php:1714
filterwidget_textreal-wp-shop-lite.php:1848
Maintenance & Trust

Real WP Shop Lite Ajax eCommerce Shopping Cart Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedMar 12, 2016
PHP min version
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Real WP Shop Lite Ajax eCommerce Shopping Cart Developer Profile

vk011

3 plugins · 40 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Real WP Shop Lite Ajax eCommerce Shopping Cart

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/real-wp-shop-lite/css/vkrwpscss.css/wp-content/plugins/real-wp-shop-lite/css/vkrwpsadmincss.css
Version Parameters
real-wp-shop-lite/css/vkrwpscss.css?ver=real-wp-shop-lite/css/vkrwpsadmincss.css?ver=

HTML / DOM Fingerprints

CSS Classes
rwps-containerabgrwps-c-innerrwpsprodprod-nameprod-descpricesprice+7 more
Data Attributes
data-offset
Shortcode Output
<div class=rwps-container<div class="cat <div class=rwpsprod><p class=addtocart>
FAQ

Frequently Asked Questions about Real WP Shop Lite Ajax eCommerce Shopping Cart