Extension WordPress

Vulnérabilités Welcart e-Commerce, page 2

Cette page rassemble les failles publiées pour Welcart e-Commerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

48Vulnérabilités
3Critiques
47Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Welcart e-Commerce

48 fiches

CVE-2022-4655 Moyenne · 6,4
Welcart e-Commerce

Welcart e-Commerce <= 2.8.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

Versions affectées

*-2.8.8

Correctif

2.8.9

Publication

23/12/2022

CVE-2022-4237 Moyenne · 6,5
Welcart e-Commerce

Welcart e-Commerce <= 2.8.5 – Authenticated (Subscriber+) Information Disclosure and PHAR deserialization

The Welcart e-Commerce plugin for WordPress is vulnerable to Information Disclosure due to missing capability checks on the wel_check_progress_ajax AJAX action in versions up to, and including, 2.8.5. This makes it possible for authenticated attackers, with subscriber-level privileges…

Versions affectées

*-2.8.5

Correctif

2.8.6

Publication

05/12/2022

CVE-2022-4140 Élevée · 7,5
Welcart e-Commerce

Welcart e-Commerce 2.6.10-2.8.4 – Information Disclosure via Arbitrary File Read

The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper file paths in the ~/functions/content-log.php file in versions 2.6.10-2.8.4. This makes it possible for unauthenticated attackers to read arbitrary files…

Versions affectées

2.6.10-2.8.4

Correctif

2.8.5

Publication

30/11/2022

CVE-2022-3935 Moyenne · 6,4
Welcart e-Commerce

Welcart e-Commerce <= 2.8.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and…

Versions affectées

*-2.8.3

Correctif

2.8.4

Publication

21/11/2022

CVE-2021-4375 Moyenne · 4,3
Welcart e-Commerce

Welcart e-Commerce < 2.2.8 – Missing Capabilities Check to Information Disclosure

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated attackers to download information…

Versions affectées

[*, 2.2.8)

Correctif

2.2.8

Publication

06/08/2021

CVE-2021-4355 Élevée · 7,5
Welcart e-Commerce

Welcart e-Commerce < 2.2.8 – Missing Capabilities Check to Information Disclosure

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible…

Versions affectées

[*, 2.2.8)

Correctif

2.2.8

Publication

06/08/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités