CVE-2023-5953: Welcart e-Commerce < 2.9.5 - Subscriber+ Arbitrary File Upload
The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJAX action handling such upload. As a result, any authenticated users, such as subscriber could upload arbitrary files, such as PHP on the server
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5953?
CVE-2023-5953 is a vulnerability in the Welcart e-Commerce WordPress plugin before version 2.9.5.
What is the severity of CVE-2023-5953?
The severity of CVE-2023-5953 is high with a CVSS score of 8.8.
What is the vulnerability description of CVE-2023-5953?
CVE-2023-5953 allows authenticated users, such as subscribers, to upload arbitrary files, including PHP, on the server.
How does CVE-2023-5953 affect the Welcart e-Commerce plugin?
CVE-2023-5953 affects Welcart e-Commerce plugin versions prior to 2.9.5.
How can I mitigate the CVE-2023-5953 vulnerability?
To mitigate the CVE-2023-5953 vulnerability, update the Welcart e-Commerce plugin to version 2.9.5 or later.