CVE-2021-4375: Welcart e-Commerce < 2.2.8 - Missing Capabilities Check to Information Disclosure
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the uscesdownloadsysteminformation() function in versions up to, and including, 2.2.7. This makes it possible for authenticated attackers to download information including WordPress settings, plugin settings, PHP settings and server settings.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-4375.
What is the severity of CVE-2021-4375?
The severity of CVE-2021-4375 is medium with a CVSS score of 4.3.
How does CVE-2021-4375 affect the Welcart e-Commerce plugin for WordPress?
CVE-2021-4375 affects the Welcart e-Commerce plugin for WordPress versions up to and including 2.2.7.
What is the impact of CVE-2021-4375?
CVE-2021-4375 allows authenticated attackers to bypass authorization and download sensitive information, including WordPress system information.
Is there a fix available for CVE-2021-4375?
Yes, a fix for CVE-2021-4375 is available. It is recommended to update the Welcart e-Commerce plugin for WordPress to a version higher than 2.2.7.