Extension WordPress
Vulnérabilités Welcart e-Commerce, page 2
Cette page rassemble les failles publiées pour Welcart e-Commerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Welcart e-Commerce
48 fiches
Welcart e-Commerce <= 2.8.21 – Authenticated(Editor+) Arbitrary File Upload
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_mail_page() function in versions up to, and including, 2.8.21. This makes it possible for authenticated attackers, with editor-level…
*-2.8.21
2.8.22
26/09/2023
Welcart e-Commerce <= 2.8.21 – Authenticated(Editor+) SQL Injection
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the order data edit page in versions up to, and including, 2.8.21 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation…
[*, 2.8.22)
2.8.22
14/09/2023
Welcart e-Commerce <= 2.8.21 – Authenticated(level_5+) SQL Injection via get_logs
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via multiple parameters in the 'get_logs' functionality in versions up to, and including, 2.8.21 due to insufficient escaping on the user supplied parameters and lack of sufficient…
[*, 2.8.22)
2.8.22
14/09/2023
Welcart e-Commerce <= 2.8.10 – Unauthenticated Stored Cross-Site Scripting
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-2.8.10
2.8.11
27/01/2023
Welcart e-Commerce <= 2.8.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-2.8.8
2.8.9
23/12/2022
Welcart e-Commerce <= 2.8.4 – Authenticated (Subscriber+) Arbitrary File Read
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper file paths in one of its AJAX actions in versions 2.6.10-2.8.4. This makes it possible for authenticated attackers, with subscriber-level…
*-2.8.4
2.8.5
05/12/2022
Welcart e-Commerce <= 2.8.5 – Authenticated (Subscriber+) Information Disclosure and PHAR deserialization
The Welcart e-Commerce plugin for WordPress is vulnerable to Information Disclosure due to missing capability checks on the wel_check_progress_ajax AJAX action in versions up to, and including, 2.8.5. This makes it possible for authenticated attackers, with subscriber-level privileges…
*-2.8.5
2.8.6
05/12/2022
Welcart e-Commerce 2.6.10-2.8.4 – Information Disclosure via Arbitrary File Read
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper file paths in the ~/functions/content-log.php file in versions 2.6.10-2.8.4. This makes it possible for unauthenticated attackers to read arbitrary files…
2.6.10-2.8.4
2.8.5
30/11/2022
Welcart e-Commerce <= 2.8.3 – Cross-Site Request Forgery
The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers…
*-2.8.3
2.8.4
28/11/2022
Welcart e-Commerce <= 2.8.3 – Missing Authorization
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on a function related to an AJAX action in versions up to, and including, 2.8.3. This makes it possible for authenticated…
*-2.8.3
2.8.4
21/11/2022
Welcart e-Commerce <= 2.8.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and…
*-2.8.3
2.8.4
21/11/2022
Welcart e-Commerce <= 2.8.3 – Cross-Site Request Forgery
The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers…
*-2.8.3
2.8.4
16/11/2022
Welcart e-Commerce 2.6.0-2.7.7 – Information Disclosure via Arbitrary File Read
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper file paths in the ~/functions/progress-check.php file in versions 2.6.0 – 2.7.7. This makes it possible for unauthenticated attackers to read…
2.6.0-2.7.7
2.7.8
02/09/2022
Welcart e-Commerce < 2.2.8 – Missing Capabilities Check to Information Disclosure
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated attackers to download information…
[*, 2.2.8)
2.2.8
06/08/2021
Welcart e-Commerce < 2.2.8 – Missing Capabilities Check to Information Disclosure
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible…
[*, 2.2.8)
2.2.8
06/08/2021
Welcart e-Commerce <= 2.2.3 – Reflected Cross-Site Scripting
Cross-site scripting vulnerability in Welcart e-Commerce versions prior to 2.2.4 allows remote attackers to inject arbitrary script or HTML via unspecified vectors.
*-2.2.3
2.2.4
11/06/2021
Welcart e-Commerce <= 2.1.0 – SQL Injection
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the 'search[order_column][0]' POST parameter in versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-2.1.0
2.1.1
08/02/2021
Welcart e-Commerce <= 1.9.35 – PHP Object Injection
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not a complete POP chain.
[*, 1.9.36)
1.9.36
05/11/2020
Welcart e-Commerce < 1.8.3 – Reflected Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-4827.
[*, 1.8.3)
1.8.3
24/06/2016
Welcart e-Commerce < 1.8.3 – Object Injection
The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data.
[*, 1.8.3)
1.8.3
24/06/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.