CVE-2025-27130: High severity welcart plugin vulnerability
Published Apr 1, 2025
·Updated
Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites created using the product.
Affected Software
2 affected components
Welcart e-Commerce<2.11.6
Welcart Welcart e-Commerce WordPress<=2.11.6
Event History
Apr 1, 2025
CVE Published
via MITRE·08:57 AM
Data Sourced
via MITRE·08:57 AM
DescriptionSeverity
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27130?
CVE-2025-27130 has a high severity rating due to its potential for arbitrary code execution by unauthenticated attackers.
2
How do I fix CVE-2025-27130?
To fix CVE-2025-27130, upgrade your Welcart e-Commerce plugin to version 2.11.7 or later.
3
Who is affected by CVE-2025-27130?
CVE-2025-27130 affects users of Welcart e-Commerce version 2.11.6 and earlier.
4
What type of vulnerability is CVE-2025-27130?
CVE-2025-27130 is classified as an untrusted data deserialization vulnerability.
5
Can CVE-2025-27130 be exploited remotely?
Yes, CVE-2025-27130 can be exploited remotely by an unauthenticated attacker.