First published: Mon Jan 02 2023(Updated: )
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Collne Welcart | <2.8.5 | |
Welcart Plugin | <2.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4140 is a vulnerability in the Welcart e-Commerce WordPress plugin before version 2.8.5 that allows an unauthenticated attacker to read arbitrary files on the server.
CVE-2022-4140 has a severity value of 7.5 (high).
CVE-2022-4140 allows an unauthenticated attacker to read arbitrary files on the server by exploiting a lack of input validation in the plugin.
The affected version of the Welcart e-Commerce WordPress plugin is before version 2.8.5.
Yes, updating the Welcart e-Commerce WordPress plugin to version 2.8.5 or later will fix CVE-2022-4140.