First published: Mon Dec 04 2023(Updated: )
The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Welcart Plugin | <2.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5951 is a vulnerability in the Welcart e-Commerce plugin for WordPress that allows for a Reflected Cross-Site Scripting attack.
The severity of CVE-2023-5951 is medium with a CVSS score of 6.1.
CVE-2023-5951 affects the Welcart e-Commerce plugin before version 2.9.5 by not properly sanitizing and escaping a parameter, which allows for a Reflected Cross-Site Scripting attack.
To fix CVE-2023-5951, users should upgrade to version 2.9.5 or later of the Welcart e-Commerce plugin.
More information about CVE-2023-5951 can be found at https://wpscan.com/vulnerability/81dc093a-545d-4bcd-ab85-ee9472d709e5.