CVE-2022-41840: WordPress Welcart eCommerce plugin <= 2.7.7 - Unauth. Directory Traversal vulnerability
Published Nov 18, 2022
·Updated
Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.
Affected Software
2 affected components
Collne Welcart E-commerce Wordpress<2.7.8
Welcart Welcart e-Commerce WordPress<2.7.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Welcart eCommerce pluginto a version that resolves this vulnerability.Fixed in 2.7.8
Event History
Nov 18, 2022
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-41840.
2
What is the severity of CVE-2022-41840?
The severity of CVE-2022-41840 is critical with a score of 9.8.
3
What is the affected software for CVE-2022-41840?
The affected software for CVE-2022-41840 is the Welcart eCommerce plugin version <= 2.7.7 running on WordPress.
4
What is the vulnerability description for CVE-2022-41840?
CVE-2022-41840 is an Unauthenticated Directory Traversal vulnerability in the Welcart eCommerce plugin version <= 2.7.7 on WordPress.
5
How can I fix CVE-2022-41840?
To fix CVE-2022-41840, update the Welcart eCommerce plugin to version 2.7.8 or later.