CVE-2023-5952
- EPSS 0.67%
- Veröffentlicht 04.12.2023 22:15:08
- Zuletzt bearbeitet 20.02.2025 18:32:30
The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog
CVE-2023-43614
- EPSS 0.24%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2023-43610
- EPSS 0.44%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
CVE-2023-43493
- EPSS 0.39%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.
CVE-2023-43484
- EPSS 0.23%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2023-41962
- EPSS 0.32%
- Veröffentlicht 27.09.2023 15:19:31
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script in the page.
CVE-2023-41233
- EPSS 0.24%
- Veröffentlicht 27.09.2023 15:19:27
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Item List page registration process of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2023-40219
- EPSS 0.46%
- Veröffentlicht 27.09.2023 15:19:02
- Zuletzt bearbeitet 20.02.2025 18:34:50
Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.
CVE-2021-4375
- EPSS 0.07%
- Veröffentlicht 07.06.2023 02:15:15
- Zuletzt bearbeitet 20.02.2025 18:34:50
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated ...
CVE-2021-4355
- EPSS 0.83%
- Veröffentlicht 07.06.2023 02:15:13
- Zuletzt bearbeitet 20.02.2025 18:34:50
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up...