CVE-2023-5952
- EPSS 1.25%
- Veröffentlicht 04.12.2023 22:15:08
- Zuletzt bearbeitet 20.02.2025 18:32:30
The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog
CVE-2023-5951
- EPSS 0.47%
- Veröffentlicht 04.12.2023 22:15:08
- Zuletzt bearbeitet 20.02.2025 18:32:30
The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-43614
- EPSS 0.62%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2023-43610
- EPSS 0.91%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
CVE-2023-43493
- EPSS 0.77%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.
CVE-2023-43484
- EPSS 0.62%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2023-41962
- EPSS 0.57%
- Veröffentlicht 27.09.2023 15:19:31
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script in the page.
CVE-2023-41233
- EPSS 0.57%
- Veröffentlicht 27.09.2023 15:19:27
- Zuletzt bearbeitet 20.02.2025 18:34:50
Cross-site scripting vulnerability in Item List page registration process of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2023-40219
- EPSS 0.95%
- Veröffentlicht 27.09.2023 15:19:02
- Zuletzt bearbeitet 20.02.2025 18:34:50
Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.
CVE-2021-4375
- EPSS 0.61%
- Veröffentlicht 07.06.2023 02:15:15
- Zuletzt bearbeitet 08.04.2026 19:17:42
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated ...