Welcart

Welcart E-commerce

36 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.67%
  • Veröffentlicht 04.12.2023 22:15:08
  • Zuletzt bearbeitet 20.02.2025 18:32:30

The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog

  • EPSS 0.24%
  • Veröffentlicht 27.09.2023 15:19:34
  • Zuletzt bearbeitet 20.02.2025 18:34:50

Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.

  • EPSS 0.44%
  • Veröffentlicht 27.09.2023 15:19:34
  • Zuletzt bearbeitet 20.02.2025 18:34:50

SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.

  • EPSS 0.39%
  • Veröffentlicht 27.09.2023 15:19:34
  • Zuletzt bearbeitet 20.02.2025 18:34:50

SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.

  • EPSS 0.23%
  • Veröffentlicht 27.09.2023 15:19:34
  • Zuletzt bearbeitet 20.02.2025 18:34:50

Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.

  • EPSS 0.32%
  • Veröffentlicht 27.09.2023 15:19:31
  • Zuletzt bearbeitet 20.02.2025 18:34:50

Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script in the page.

  • EPSS 0.24%
  • Veröffentlicht 27.09.2023 15:19:27
  • Zuletzt bearbeitet 20.02.2025 18:34:50

Cross-site scripting vulnerability in Item List page registration process of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.

  • EPSS 0.46%
  • Veröffentlicht 27.09.2023 15:19:02
  • Zuletzt bearbeitet 20.02.2025 18:34:50

Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 07.06.2023 02:15:15
  • Zuletzt bearbeitet 20.02.2025 18:34:50

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated ...

Exploit
  • EPSS 0.83%
  • Veröffentlicht 07.06.2023 02:15:13
  • Zuletzt bearbeitet 20.02.2025 18:34:50

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up...