First published: Sat Nov 07 2020(Updated: )
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not a complete POP chain.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Collne Welcart | <1.9.36 | |
Welcart Plugin | <1.9.36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28339 is a vulnerability in the usc-e-shop (Collne Welcart e-Commerce) plugin before version 1.9.36 for WordPress that allows Object Injection.
The severity of CVE-2020-28339 is high with a CVSS severity score of 8.8.
CVE-2020-28339 allows Object Injection in the usc-e-shop plugin, which can potentially lead to unauthorized access and impact the security of WordPress websites.
To fix CVE-2020-28339, you should update the usc-e-shop (Collne Welcart e-Commerce) plugin to version 1.9.36 or newer.
You can find more information about CVE-2020-28339 on the official WordPress plugin page for usc-e-shop and the Wordfence blog.