Extension WordPress
Vulnérabilités Welcart e-Commerce, page 2
Cette page rassemble les failles publiées pour Welcart e-Commerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Welcart e-Commerce
53 fiches
Welcart e-Commerce <= 2.9.5 – Authenticated (Administrator+) PHP Object Injection
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 2.9.5 (inclusive) via deserialization of untrusted input in the welcart_confirm_check_ajax function. This makes it possible for administrators to inject a PHP…
[*, 2.9.6)
2.9.6
15/11/2023
Welcart e-Commerce <= 2.9.4 – Authenticated (Subscriber+) Arbitrary File Upload
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_certificate_file function in all versions up to, and including, 2.9.4. This makes it possible for subscribers or higher…
*-2.9.4
2.9.5
14/11/2023
Welcart e-Commerce <= 2.9.4 – Cross-Site Request Forgery
The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.4. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated…
*-2.9.4
2.9.5
14/11/2023
Welcart e-Commerce <= 2.9.4 – Unauthenticated PHP Object Injection
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.9.4 via deserialization of untrusted input from a cookie in this plugin. This makes it possible for unauthenticated attackers…
*-2.9.4
2.9.5
10/11/2023
Welcart e-Commerce <= 2.9.4 – Reflected Cross-Site Scripting
The Welcart e-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'upload_mode' parameter in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-2.9.4
2.9.5
10/11/2023
Welcart e-Commerce <= 2.8.21 – Authenticated(Editor+) Arbitrary File Upload
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_mail_page() function in versions up to, and including, 2.8.21. This makes it possible for authenticated attackers, with editor-level…
*-2.8.21
2.8.22
26/09/2023
Welcart e-Commerce <= 2.8.21 – Authenticated(Editor+) SQL Injection
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the order data edit page in versions up to, and including, 2.8.21 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation…
[*, 2.8.22)
2.8.22
14/09/2023
Welcart e-Commerce <= 2.8.21 – Authenticated(level_5+) SQL Injection via get_logs
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via multiple parameters in the 'get_logs' functionality in versions up to, and including, 2.8.21 due to insufficient escaping on the user supplied parameters and lack of sufficient…
[*, 2.8.22)
2.8.22
14/09/2023
Welcart e-Commerce <= 2.8.10 – Unauthenticated Stored Cross-Site Scripting
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-2.8.10
2.8.11
27/01/2023
Welcart e-Commerce <= 2.8.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-2.8.8
2.8.9
23/12/2022
Welcart e-Commerce <= 2.8.4 – Authenticated (Subscriber+) Arbitrary File Read
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper file paths in one of its AJAX actions in versions 2.6.10-2.8.4. This makes it possible for authenticated attackers, with subscriber-level…
*-2.8.4
2.8.5
05/12/2022
Welcart e-Commerce <= 2.8.5 – Authenticated (Subscriber+) Information Disclosure and PHAR deserialization
The Welcart e-Commerce plugin for WordPress is vulnerable to Information Disclosure due to missing capability checks on the wel_check_progress_ajax AJAX action in versions up to, and including, 2.8.5. This makes it possible for authenticated attackers, with subscriber-level privileges…
*-2.8.5
2.8.6
05/12/2022
Welcart e-Commerce 2.6.10-2.8.4 – Information Disclosure via Arbitrary File Read
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper file paths in the ~/functions/content-log.php file in versions 2.6.10-2.8.4. This makes it possible for unauthenticated attackers to read arbitrary files…
2.6.10-2.8.4
2.8.5
30/11/2022
Welcart e-Commerce <= 2.8.3 – Cross-Site Request Forgery
The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers…
*-2.8.3
2.8.4
28/11/2022
Welcart e-Commerce <= 2.8.3 – Missing Authorization
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on a function related to an AJAX action in versions up to, and including, 2.8.3. This makes it possible for authenticated…
*-2.8.3
2.8.4
21/11/2022
Welcart e-Commerce <= 2.8.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and…
*-2.8.3
2.8.4
21/11/2022
Welcart e-Commerce <= 2.8.3 – Cross-Site Request Forgery
The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers…
*-2.8.3
2.8.4
16/11/2022
Welcart e-Commerce 2.6.0-2.7.7 – Information Disclosure via Arbitrary File Read
The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper file paths in the ~/functions/progress-check.php file in versions 2.6.0 – 2.7.7. This makes it possible for unauthenticated attackers to read…
2.6.0-2.7.7
2.7.8
02/09/2022
Welcart e-Commerce < 2.2.8 – Missing Capabilities Check to Information Disclosure
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated attackers to download information…
[*, 2.2.8)
2.2.8
06/08/2021
Welcart e-Commerce < 2.2.8 – Missing Capabilities Check to Information Disclosure
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible…
[*, 2.2.8)
2.2.8
06/08/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.