Uscnanbu Welcart E-Commerce vulnerabilities
8 known vulnerabilities affecting uscnanbu/welcart_e-commerce.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM7LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-12979MEDIUMCVSS 5.3≤ 2.11.242025-11-13
CVE-2025-12979 [MEDIUM] CWE-862 CVE-2025-12979: The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi
The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' action in all versions up to, and including, 2.11.24. This makes it possible for unauthenticated attackers to access configured payment credentials (ex. PayPal api secret) , as well as business contact deta
cvelistv5nvd
CVE-2025-10651MEDIUMCVSS 5.5≤ 2.11.222025-10-22
CVE-2025-10651 [MEDIUM] CWE-79 CVE-2025-10651: The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'or
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in versions up to, and including, 2.11.22. This is due to insufficient sanitization on the order_mail field and a lack of escaping on output. This makes it possible for authenticated attackers, with Editor-level permissions and above,
cvelistv5nvd
CVE-2025-10649MEDIUMCVSS 6.5≤ 2.11.212025-10-08
CVE-2025-10649 [MEDIUM] CWE-89 CVE-2025-10649: The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all ver
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and including, 2.11.21 due to insufficient escaping on the user supplied value and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append
cvelistv5nvd
CVE-2025-9367MEDIUMCVSS 5.5≤ 2.11.202025-09-10
CVE-2025-9367 [MEDIUM] CWE-79 CVE-2025-9367: The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via setting
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will ex
cvelistv5nvd
CVE-2025-0511MEDIUMCVSS 6.1≤ 2.11.92025-02-12
CVE-2025-0511 [MEDIUM] CWE-79 CVE-2025-0511: The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘na
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesse
cvelistv5nvd
CVE-2023-6120LOWCVSS 2.7≤ 2.9.62023-12-09
CVE-2023-6120 [LOW] CWE-22 CVE-2023-6120: The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up
The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the upload_certificate_file function. This makes it possible for administrators to upload .pem or .crt files to arbitrary locations on the server.
cvelistv5nvd
CVE-2021-4375MEDIUMCVSS 4.3fixed in 2.2.82023-06-07
CVE-2021-4375 [MEDIUM] CWE-862 CVE-2021-4375: The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing c
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated attackers to download information including WordPress settings, plugin settings, PHP settings and serve
cvelistv5nvd
CVE-2021-4355MEDIUMCVSS 5.3fixed in 2.2.82023-06-07
CVE-2021-4355 [MEDIUM] CWE-862 CVE-2021-4355: The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing cap
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to download lists of me
cvelistv5nvd