First published: Mon Dec 04 2023(Updated: )
The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Welcart Plugin | <2.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5952 is a vulnerability in the Welcart e-Commerce WordPress plugin before version 2.9.5 that allows unauthenticated users to perform PHP Object Injection.
CVE-2023-5952 works by unserializing user input from cookies, which can lead to PHP Object Injection if a suitable gadget is present on the blog.
CVE-2023-5952 has a severity keyword of 'critical' and a severity value of 9.8.
The Welcart e-Commerce WordPress plugin before version 2.9.5 is affected by CVE-2023-5952.
To fix CVE-2023-5952, you should update the Welcart e-Commerce plugin to version 2.9.5 or higher.