First published: Tue Apr 01 2025(Updated: )
Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites created using the product.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Welcart Plugin | <2.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27130 has a high severity rating due to its potential for arbitrary code execution by unauthenticated attackers.
To fix CVE-2025-27130, upgrade your Welcart e-Commerce plugin to version 2.11.7 or later.
CVE-2025-27130 affects users of Welcart e-Commerce version 2.11.6 and earlier.
CVE-2025-27130 is classified as an untrusted data deserialization vulnerability.
Yes, CVE-2025-27130 can be exploited remotely by an unauthenticated attacker.