📦 Welcart E Commerce

by Welcart

🔍 What is Welcart E Commerce?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-5952

CRITICAL CVSS 9.8 Dec 4, 2023

The Welcart e-Commerce WordPress plugin before version 2.9.5 contains a PHP object injection vulnerability due to unsafe deserialization of user-controlled cookie data. Unauthenticated attackers can e...

CVE-2025-27130

HIGH CVSS 8.8 Apr 1, 2025

Welcart e-Commerce versions 2.11.6 and earlier contain an untrusted data deserialization vulnerability that allows remote unauthenticated attackers to execute arbitrary code. This affects any website ...

CVE-2025-0511

HIGH CVSS 7.2 Feb 12, 2025

The Welcart e-Commerce plugin for WordPress has a stored cross-site scripting (XSS) vulnerability in the 'name' parameter that allows unauthenticated attackers to inject malicious scripts. These scrip...

CVE-2023-43610

HIGH CVSS 8.8 Sep 27, 2023

This SQL injection vulnerability in Welcart e-Commerce allows authenticated users with editor privileges or higher to execute arbitrary SQL commands on the database. It affects versions 2.7 through 2....

CVE-2023-40219

HIGH CVSS 7.2 Sep 27, 2023

This vulnerability in Welcart e-Commerce allows users with editor or higher privileges to upload arbitrary files to unauthorized directories. This could lead to remote code execution or data manipulat...

CVE-2023-22705

HIGH CVSS 7.1 Mar 29, 2023

This vulnerability allows unauthenticated attackers to inject malicious scripts into Welcart e-Commerce plugin pages, which execute in victims' browsers when they visit crafted URLs. It affects WordPr...

CVE-2024-45366

MEDIUM CVSS 6.1 Sep 18, 2024

Welcart e-Commerce versions before 2.11.2 contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. When exploited, these scripts execute in ...