CVE-2023-5953
- EPSS 0.48%
- Veröffentlicht 04.12.2023 22:15:08
- Zuletzt bearbeitet 29.05.2025 14:15:33
The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJAX action handling such upload. As a result, any authenticated users, such as subscriber could upload...
CVE-2023-5952
- EPSS 1.25%
- Veröffentlicht 04.12.2023 22:15:08
- Zuletzt bearbeitet 20.02.2025 18:32:30
The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog
CVE-2023-5951
- EPSS 0.47%
- Veröffentlicht 04.12.2023 22:15:08
- Zuletzt bearbeitet 20.02.2025 18:32:30
The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-43614
- EPSS 0.62%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2023-43610
- EPSS 0.91%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
CVE-2023-43493
- EPSS 0.77%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.
CVE-2023-43484
- EPSS 0.62%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2023-41962
- EPSS 0.57%
- Veröffentlicht 27.09.2023 15:19:31
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script in the page.
CVE-2023-41233
- EPSS 0.57%
- Veröffentlicht 27.09.2023 15:19:27
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Item List page registration process of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2023-40219
- EPSS 0.95%
- Veröffentlicht 27.09.2023 15:19:02
- Zuletzt bearbeitet 20.02.2025 18:34:50
Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.