cleantalk
Vulnerabilities and Security Researches

Welcart e-Commerce, 4189c7265f663f4e26346be3f437477a768af0f6

Application

Welcart e-Commerce

Published on
Aug 06, 2021
Research Description
Welcart e-Commerce [usc-e-shop] < 2.2.8 Welcart e-Commerce < 2.2.8 - Missing Capabilities Check to Information Disclosure The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to download lists of members, products and orders.
Affected versions
max 2.2.8.
Status
vulnerable