Extension WordPress
Vulnérabilités Welcart e-Commerce
Cette page rassemble les failles publiées pour Welcart e-Commerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Welcart e-Commerce
48 fiches
Welcart e-Commerce <= 2.11.28 – Missing Authorization
The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.11.28. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-2.11.28
2.11.29
04/06/2026
Welcart e-Commerce <= 2.11.24 – Missing Authorization to Unauthenticated Information Exposure
The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' action in all versions up to, and including, 2.11.24. This makes it possible for unauthenticated attackers…
*-2.11.24
2.11.25
12/11/2025
Welcart e-Commerce <= 2.11.22 – Authenticated (Editor+) Stored Cross-Site Scripting via order_mail
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in versions up to, and including, 2.11.22. This is due to insufficient sanitization on the order_mail field and a lack of escaping…
*-2.11.22
2.11.23
21/10/2025
Welcart e-Commerce <= 2.11.24 – Missing Authorization
The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.11.24. This makes it possible for authenticated attackers, with subscriber-level access and…
*-2.11.24
2.11.25
14/10/2025
Welcart e-Commerce <= 2.11.21 – Authenticated (Author+) SQL Injection via Cookie
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and including, 2.11.21 due to insufficient escaping on the user supplied value and lack of sufficient preparation on the…
*-2.11.21
2.11.22
07/10/2025
Welcart e-Commerce <= 2.11.20 – Authenticated (Editor+) Stored Cross-Site Scripting
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-2.11.20
2.11.21
09/09/2025
Welcart e-Commerce <= 2.11.20 – Authenticated (Editor+) Stored Cross-Site Scripting
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-2.11.20
2.11.21
09/09/2025
Welcart e-Commerce <= 2.11.16 – Authenticated (Editor+) PHP Object Injection
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.11.16 via deserialization of untrusted input. This makes it possible for authenticated attackers, with editor-level access and above, to inject…
*-2.11.16
2.11.17
12/08/2025
Welcart e-Commerce <= 2.11.16 – Authenticated (Editor+) Stored Cross-Site Scripting
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-2.11.16
2.11.17
16/07/2025
Welcart e-Commerce <= 2.11.13 – Authenticated (Editor+) Arbitrary File Deletion
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 2.11.13. This makes it possible for authenticated attackers, with Editor-level…
*-2.11.13
2.11.14
03/06/2025
Welcart e-Commerce <= 2.11.9 – Unauthenticated Stored Cross-Site Scripting via name Parameter
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-2.11.9
2.11.10
11/02/2025
Welcart e-Commerce <= 2.11.1 – Authenticated (Admin+) SQL Injection
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.11.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-2.11.1
2.11.2
18/09/2024
Welcart e-Commerce <= 2.9.14 – Missing Authorization
The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the usces_item_duplicate() function in versions up to, and including, 2.9.14. This makes it possible for authenticated attackers, with author-level access…
*-2.9.14
2.10.0
12/04/2024
Welcart e-Commerce <= 2.9.3 – Authenticated(Editor+) SQL Injection
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 2.9.4 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
[*, 2.9.4)
2.9.4
21/12/2023
Welcart e-Commerce <= 2.9.6 – Authenticated (Administrator+) Directory Traversal
The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the upload_certificate_file function. This makes it possible for administrators to upload .pem or .crt files to arbitrary locations…
*-2.9.6
2.9.7
08/12/2023
Welcart e-Commerce <= 2.9.5 – Authenticated (Administrator+) PHP Object Injection
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 2.9.5 (inclusive) via deserialization of untrusted input in the welcart_confirm_check_ajax function. This makes it possible for administrators to inject a PHP…
[*, 2.9.6)
2.9.6
15/11/2023
Welcart e-Commerce <= 2.9.4 – Authenticated (Subscriber+) Arbitrary File Upload
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_certificate_file function in all versions up to, and including, 2.9.4. This makes it possible for subscribers or higher…
*-2.9.4
2.9.5
14/11/2023
Welcart e-Commerce <= 2.9.4 – Cross-Site Request Forgery
The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.4. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated…
*-2.9.4
2.9.5
14/11/2023
Welcart e-Commerce <= 2.9.4 – Unauthenticated PHP Object Injection
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.9.4 via deserialization of untrusted input from a cookie in this plugin. This makes it possible for unauthenticated attackers…
*-2.9.4
2.9.5
10/11/2023
Welcart e-Commerce <= 2.9.4 – Reflected Cross-Site Scripting
The Welcart e-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'upload_mode' parameter in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-2.9.4
2.9.5
10/11/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.