Welcart e-Commerce, 4189c7265f663f4e26346be3f437477a768af0f6
- CVE, Research URL
- Home page URL
- Application
- Published on
- Aug 06, 2021
- Research Description
- Welcart e-Commerce [usc-e-shop] < 2.2.8 Welcart e-Commerce < 2.2.8 - Missing Capabilities Check to Information Disclosure The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to download lists of members, products and orders.
- Affected versions
-
max 2.2.8.
- Status
-
vulnerable