CVE-2022-4236: Welcart e-Commerce < 2.8.5 - Subscriber+ Arbitrary File Access
Published Jan 2, 2023
·Updated
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a role as low as subscriber to read arbitrary files on the server.
Affected Software
2 affected components
Collne Welcart E-commerce Wordpress<2.8.5
Welcart Welcart e-Commerce WordPress<2.8.5
Event History
Jan 2, 2023
CVE Published
via MITRE·09:49 PM
Data Sourced
via MITRE·09:49 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-4236.
2
What is the severity of CVE-2022-4236?
The severity of CVE-2022-4236 is medium with a CVSS score of 6.5.
3
Which software is affected by CVE-2022-4236?
The Welcart e-Commerce WordPress plugin before version 2.8.5 is affected by CVE-2022-4236.
4
What is the impact of CVE-2022-4236?
CVE-2022-4236 allows users with a role as low as subscriber to read arbitrary files on the server.
5
How can I fix CVE-2022-4236?
To fix CVE-2022-4236, update the Welcart e-Commerce WordPress plugin to version 2.8.5 or later.