Welcart e-Commerce, d099ab511b85fb4329d1dda5d0149839e3687185
- CVE, Research URL
- Home page URL
- Application
- Published on
- Nov 15, 2023
- Research Description
- Welcart e-Commerce [usc-e-shop] < 2.9.6 WordPress Welcart e-Commerce Plugin < 2.9.6 is vulnerable to PHP Object Injection Update the WordPress Welcart e-Commerce plugin to the latest available version (at least 2.9.6). WordFence discovered and reported this PHP Object Injection vulnerability in WordPress Welcart e-Commerce Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 2.9.6.
- Affected versions
-
max 2.9.6.
- Status
-
vulnerable