CVE-2022-3935: Welcart e-Commerce < 2.8.4 - Multiple Subscriber+ Stored Cross-Site Scripting
Published Dec 12, 2022
·Updated
The Welcart e-Commerce WordPress plugin before 2.8.4 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
Affected Software
2 affected components
Collne Welcart E-commerce Wordpress<2.8.4
Welcart Welcart e-Commerce WordPress<2.8.4
Event History
Dec 12, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-3935.
2
What is the severity of CVE-2022-3935?
The severity of CVE-2022-3935 is medium with a CVSS score of 5.4.
3
What is the affected software?
The affected software is the Welcart e-Commerce WordPress plugin before version 2.8.4.
4
What type of vulnerability is CVE-2022-3935?
CVE-2022-3935 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
Is authentication required to exploit CVE-2022-3935?
Yes, authentication is required to exploit CVE-2022-3935.