CVE-2022-3946: Welcart e-Commerce < 2.8.4 - Subscriber+ Arbitrary Shipping Method Creation/Update/Deletion
The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Welcart e-Commerce WordPress plugin vulnerability?
The vulnerability ID for this Welcart e-Commerce WordPress plugin vulnerability is CVE-2022-3946.
What is the severity of CVE-2022-3946?
The severity of CVE-2022-3946 is medium, with a severity value of 6.5.
What is the impact of CVE-2022-3946?
CVE-2022-3946 allows any logged-in user to create, update, and delete shipping methods in the Welcart e-Commerce WordPress plugin before version 2.8.4.
How can I fix CVE-2022-3946?
To fix CVE-2022-3946, you should update the Welcart e-Commerce WordPress plugin to version 2.8.4 or higher.
Where can I find more information about CVE-2022-3946?
You can find more information about CVE-2022-3946 at the following reference: https://wpscan.com/vulnerability/b48e4e1d-e682-4b16-81dc-2feee78d7ed0