CVE-2023-50847: WordPress Welcart e-Commerce Plugin <= 2.9.3 is vulnerable to SQL Injection
Published Dec 28, 2023
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Collne Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.3.
Affected Software
1 affected component
Welcart Welcart e-Commerce WordPress<=2.9.3
Remediation
Information
Update to 2.9.4 or higher version.
Event History
Dec 28, 2023
CVE Published
via MITRE·06:15 PM
Data Sourced
via MITRE·06:15 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50847?
CVE-2023-50847 has a critical severity level due to its potential for SQL injection attacks.
2
How do I fix CVE-2023-50847?
To fix CVE-2023-50847, users should update Welcart e-Commerce to the latest version beyond 2.9.3.
3
What software is affected by CVE-2023-50847?
CVE-2023-50847 affects Welcart e-Commerce versions up to 2.9.3.
4
What type of vulnerability is CVE-2023-50847?
CVE-2023-50847 is an SQL injection vulnerability resulting from improper neutralization of special elements.
5
Can CVE-2023-50847 lead to data compromise?
Yes, CVE-2023-50847 can lead to unauthorized access and compromise of sensitive data through SQL injection.