CVE-2023-5952: Welcart e-Commerce < 2.9.5 - Unauthenticated PHP Object Injection
The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5952?
CVE-2023-5952 is a vulnerability in the Welcart e-Commerce WordPress plugin before version 2.9.5 that allows unauthenticated users to perform PHP Object Injection.
How does CVE-2023-5952 work?
CVE-2023-5952 works by unserializing user input from cookies, which can lead to PHP Object Injection if a suitable gadget is present on the blog.
What is the severity of CVE-2023-5952?
CVE-2023-5952 has a severity keyword of 'critical' and a severity value of 9.8.
What software is affected by CVE-2023-5952?
The Welcart e-Commerce WordPress plugin before version 2.9.5 is affected by CVE-2023-5952.
How can I fix CVE-2023-5952?
To fix CVE-2023-5952, you should update the Welcart e-Commerce plugin to version 2.9.5 or higher.