Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2022-41840Path Traversal in E-commerce

CWE-22Path Traversal5 documents5 sources
Severity
9.8CRITICALNVD
CNA7.5VulnCheck7.5
EPSS
79.4%
top 0.92%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 18

Description

Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

3
CVEList
WordPress Welcart eCommerce plugin <= 2.7.7 - Unauth. Directory Traversal vulnerability2022-11-18
GHSA
GHSA-9w9j-rrw6-jgxm: Unauth2022-11-18
VulnCheck
welcart welcart_e-commerce Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2022

💥Exploits & PoCs

1
Nuclei
Welcart eCommerce <=2.7.7 - Local File Inclusion
CVE-2022-41840 — Path Traversal in Welcart E-commerce | cvebase