CVE-2022-4140: Welcart e-Commerce < 2.8.5 - Unauthenticated Arbitrary File Access
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4140?
CVE-2022-4140 is a vulnerability in the Welcart e-Commerce WordPress plugin before version 2.8.5 that allows an unauthenticated attacker to read arbitrary files on the server.
How severe is CVE-2022-4140?
CVE-2022-4140 has a severity value of 7.5 (high).
How does CVE-2022-4140 impact the Welcart e-Commerce WordPress plugin?
CVE-2022-4140 allows an unauthenticated attacker to read arbitrary files on the server by exploiting a lack of input validation in the plugin.
What is the affected version of the Welcart e-Commerce WordPress plugin?
The affected version of the Welcart e-Commerce WordPress plugin is before version 2.8.5.
Is there a fix for CVE-2022-4140?
Yes, updating the Welcart e-Commerce WordPress plugin to version 2.8.5 or later will fix CVE-2022-4140.