Show filters
34 Total Results
Displaying 11-20 of 34
Sort by:
Attacker Value
Unknown

CVE-2023-43610

Disclosure Date: September 27, 2023 (last updated February 21, 2025)
SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
Attacker Value
Unknown

CVE-2023-43493

Disclosure Date: September 27, 2023 (last updated February 21, 2025)
SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.
Attacker Value
Unknown

CVE-2023-43484

Disclosure Date: September 27, 2023 (last updated February 21, 2025)
Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
Attacker Value
Unknown

CVE-2023-41962

Disclosure Date: September 27, 2023 (last updated February 21, 2025)
Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script in the page.
Attacker Value
Unknown

CVE-2023-41233

Disclosure Date: September 27, 2023 (last updated February 21, 2025)
Cross-site scripting vulnerability in Item List page registration process of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
Attacker Value
Unknown

CVE-2023-40219

Disclosure Date: September 27, 2023 (last updated February 21, 2025)
Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.
Attacker Value
Unknown

CVE-2021-4375

Disclosure Date: June 07, 2023 (last updated February 21, 2025)
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated attackers to download information including WordPress settings, plugin settings, PHP settings and server settings.
Attacker Value
Unknown

CVE-2021-4355

Disclosure Date: June 07, 2023 (last updated February 21, 2025)
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to download lists of members, products and orders.
Attacker Value
Unknown

CVE-2023-22705

Disclosure Date: March 29, 2023 (last updated February 21, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Collne Inc. Welcart e-Commerce plugin <= 2.8.10 versions.
Attacker Value
Unknown

CVE-2022-4655

Disclosure Date: January 16, 2023 (last updated February 21, 2025)
The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.