CVE-2020-28339: High severity collne welcart vulnerability
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of uscesunserialize. There is not a complete POP chain.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28339?
CVE-2020-28339 is a vulnerability in the usc-e-shop (Collne Welcart e-Commerce) plugin before version 1.9.36 for WordPress that allows Object Injection.
What is the severity of CVE-2020-28339?
The severity of CVE-2020-28339 is high with a CVSS severity score of 8.8.
How does CVE-2020-28339 impact WordPress?
CVE-2020-28339 allows Object Injection in the usc-e-shop plugin, which can potentially lead to unauthorized access and impact the security of WordPress websites.
How can I fix CVE-2020-28339 in usc-e-shop plugin on WordPress?
To fix CVE-2020-28339, you should update the usc-e-shop (Collne Welcart e-Commerce) plugin to version 1.9.36 or newer.
Where can I find more information about CVE-2020-28339?
You can find more information about CVE-2020-28339 on the official WordPress plugin page for usc-e-shop and the Wordfence blog.