cleantalk
Vulnerabilities and Security Researches

Welcart e-Commerce, d099ab511b85fb4329d1dda5d0149839e3687185

Application

Welcart e-Commerce

Published on
Nov 15, 2023
Research Description
Welcart e-Commerce [usc-e-shop] < 2.9.6 WordPress Welcart e-Commerce Plugin < 2.9.6 is vulnerable to PHP Object Injection Update the WordPress Welcart e-Commerce plugin to the latest available version (at least 2.9.6). WordFence discovered and reported this PHP Object Injection vulnerability in WordPress Welcart e-Commerce Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 2.9.6.
Affected versions
max 2.9.6.
Status
vulnerable