First published: Mon Jan 16 2023(Updated: )
The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Collne Welcart | <2.8.9 | |
<2.8.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4655 is a vulnerability in the Welcart e-Commerce WordPress plugin that allows users with a low role, such as a contributor, to perform a Stored Cross-Site Scripting attack.
The severity of CVE-2022-4655 is medium with a CVSS score of 5.4.
CVE-2022-4655 affects the Welcart e-Commerce WordPress plugin before version 2.8.9 by allowing users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.
To fix CVE-2022-4655, you should update the Welcart e-Commerce WordPress plugin to version 2.8.9 or later.
You can find more information about CVE-2022-4655 at the following reference link: https://wpscan.com/vulnerability/a1c70c80-e952-4cc7-aca0-c2dde3fa08a9