Welcart

Welcart E-commerce

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.25%
  • Veröffentlicht 04.12.2023 22:15:08
  • Zuletzt bearbeitet 20.02.2025 18:32:30

The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog

Exploit
  • EPSS 0.47%
  • Veröffentlicht 04.12.2023 22:15:08
  • Zuletzt bearbeitet 20.02.2025 18:32:30

The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • EPSS 0.62%
  • Veröffentlicht 27.09.2023 15:19:34
  • Zuletzt bearbeitet 20.02.2025 18:34:50

Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.

  • EPSS 0.91%
  • Veröffentlicht 27.09.2023 15:19:34
  • Zuletzt bearbeitet 20.02.2025 18:34:50

SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.

  • EPSS 0.77%
  • Veröffentlicht 27.09.2023 15:19:34
  • Zuletzt bearbeitet 20.02.2025 18:34:50

SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.

  • EPSS 0.62%
  • Veröffentlicht 27.09.2023 15:19:34
  • Zuletzt bearbeitet 20.02.2025 18:34:50

Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.

  • EPSS 0.57%
  • Veröffentlicht 27.09.2023 15:19:31
  • Zuletzt bearbeitet 20.02.2025 18:34:50

Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script in the page.

  • EPSS 0.57%
  • Veröffentlicht 27.09.2023 15:19:27
  • Zuletzt bearbeitet 20.02.2025 18:34:50

Cross-site scripting vulnerability in Item List page registration process of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.

  • EPSS 0.95%
  • Veröffentlicht 27.09.2023 15:19:02
  • Zuletzt bearbeitet 20.02.2025 18:34:50

Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 07.06.2023 02:15:15
  • Zuletzt bearbeitet 08.04.2026 19:17:42

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated ...