First published: Mon Dec 12 2022(Updated: )
The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Collne Welcart | <2.8.4 | |
<2.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Welcart e-Commerce WordPress plugin vulnerability is CVE-2022-3946.
The severity of CVE-2022-3946 is medium, with a severity value of 6.5.
CVE-2022-3946 allows any logged-in user to create, update, and delete shipping methods in the Welcart e-Commerce WordPress plugin before version 2.8.4.
To fix CVE-2022-3946, you should update the Welcart e-Commerce WordPress plugin to version 2.8.4 or higher.
You can find more information about CVE-2022-3946 at the following reference: https://wpscan.com/vulnerability/b48e4e1d-e682-4b16-81dc-2feee78d7ed0