CVE-2015-2973: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Welcart plugin before 1.4.18 for WordPress allow remote attackers to inject arbitrary web script or HTML via the uscesreferer parameter to (1) classes/usceshop.class.php, (2) includes/edit-form-advanced.php, (3) includes/edit-form-advanced30.php, (4) includes/edit-form-advanced34.php, (5) includes/membereditform.php, (6) includes/ordereditform.php, (7) includes/orderlist.php, or (8) includes/uscesitemmasterlist.php, related to admin.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2973?
CVE-2015-2973 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2015-2973?
To fix CVE-2015-2973, upgrade the Welcart plugin to version 1.4.18 or later.
What causes CVE-2015-2973?
CVE-2015-2973 is caused by insufficient input validation in the usces_referer parameter, allowing for XSS exploitation.
Who is affected by CVE-2015-2973?
CVE-2015-2973 affects users of the Welcart plugin for WordPress versions prior to 1.4.18.
What is the impact of CVE-2015-2973?
The impact of CVE-2015-2973 includes potential unauthorized execution of scripts in the context of a user's browser.