Welcart e-Commerce, 87d99d4485bb686d23bf4cc14a7a45c46e85a6bc
- CVE, Research URL
- Home page URL
- Application
- Published on
- Nov 15, 2023
- Research Description
- Welcart e-Commerce [usc-e-shop] < 2.9.6 Welcart e-Commerce <= 2.9.5 - Authenticated (Administrator+) PHP Object Injection The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 2.9.5 (inclusive) via deserialization of untrusted input in the welcart_confirm_check_ajax function. This makes it possible for administrators to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
- Affected versions
-
max 2.9.6.
- Status
-
vulnerable