CVE-2023-6120: Welcart e-Commerce <= 2.9.6 - Authenticated (Administrator+) Directory Traversal
The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the uploadcertificatefile function. This makes it possible for administrators to upload .pem or .crt files to arbitrary locations on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6120?
CVE-2023-6120 has a high severity rating due to its potential to allow unauthorized file uploads.
How do I fix CVE-2023-6120?
To fix CVE-2023-6120, update the Welcart e-Commerce plugin to version 2.9.7 or later.
Which versions are affected by CVE-2023-6120?
All versions of the Welcart e-Commerce plugin up to and including 2.9.6 are affected by CVE-2023-6120.
What types of files can be uploaded due to CVE-2023-6120?
CVE-2023-6120 allows the upload of .pem and .crt files to arbitrary locations on the server.
Who is primarily impacted by CVE-2023-6120?
Administrators using the vulnerable versions of the Welcart e-Commerce plugin are primarily impacted by CVE-2023-6120.