Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total11
Critical1
High3
Medium7
Reset
Showing 1-11 of 11 records
Threat Entry Updated 2025-11-14

CVE-2025-12979 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' action in all versions up to, and including, 2.11.24. This makes it possible for unauthenticated attackers to access configured payment credentials (ex. PayPal api secret) , as well as business contact details, mail templates, and other operational settings tied to the store.

PLUGIN Welcart E Commerce

CVE-2025-12979

MEDIUM CVSS 5.3 2025-11-13
Threat Entry Updated 2025-10-22

CVE-2025-10651 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in versions up to, and including, 2.11.22. This is due to insufficient sanitization on the order_mail field and a lack of escaping on output. This makes it possible for authenticated attackers, with Editor-level permissions and above, to inject arbitrary web scripts via the General Setting page that will execute when an administrator accesses the E-mail Setting page.

PLUGIN Welcart E Commerce

CVE-2025-10651

MEDIUM CVSS 5.5 2025-10-22
Threat Entry Updated 2025-10-08

CVE-2025-10649 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and including, 2.11.21 due to insufficient escaping on the user supplied value and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Welcart E Commerce

CVE-2025-10649

MEDIUM CVSS 6.5 2025-10-08
Threat Entry Updated 2025-09-11

CVE-2025-9367 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Welcart E Commerce

CVE-2025-9367

MEDIUM CVSS 5.5 2025-09-10
Threat Entry Updated 2025-02-20

CVE-2025-0511 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Welcart E Commerce

CVE-2025-0511

HIGH CVSS 7.2 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2023-6120 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the upload_certificate_file function. This makes it possible for administrators to upload .pem or .crt files to arbitrary locations on the server.

PLUGIN Welcart E Commerce

CVE-2023-6120

MEDIUM CVSS 4.1 2023-12-09
Threat Entry Updated 2025-02-20

CVE-2023-5952 - Welcart E Commerce Plugin

The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog

PLUGIN Welcart E Commerce

CVE-2023-5952

CRITICAL CVSS 9.8 2023-12-04
Threat Entry Updated 2025-05-29

CVE-2023-5953 - Welcart E Commerce Plugin

The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJAX action handling such upload. As a result, any authenticated users, such as subscriber could upload arbitrary files, such as PHP on the server

PLUGIN Welcart E Commerce

CVE-2023-5953

HIGH CVSS 8.8 2023-12-04
Threat Entry Updated 2025-02-20

CVE-2023-5951 - Welcart E Commerce Plugin

The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Welcart E Commerce

CVE-2023-5951

MEDIUM CVSS 6.1 2023-12-04
Threat Entry Updated 2026-04-08

CVE-2021-4375 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated attackers to download information including WordPress settings, plugin settings, PHP settings and server settings.

PLUGIN Welcart E Commerce

CVE-2021-4375

MEDIUM CVSS 4.3 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4355 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to download lists of members, products and orders.

PLUGIN Welcart E Commerce

CVE-2021-4355

HIGH CVSS 7.5 2023-06-07
Scroll to top