CVE-2025-47511: WordPress Welcart e-Commerce plugin <= 2.11.13 - Arbitrary File Deletion Vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Path Traversal.This issue affects Welcart e-Commerce: from n/a through <= 2.11.13.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47511?
CVE-2025-47511 is rated as a medium-severity vulnerability due to its potential for exploitation through path traversal.
How does CVE-2025-47511 allow unauthorized access?
CVE-2025-47511 enables path traversal, which allows attackers to access files outside the intended directory.
What versions of Welcart e-Commerce are affected by CVE-2025-47511?
CVE-2025-47511 affects Welcart e-Commerce versions from n/a up to 2.11.13.
How do I fix CVE-2025-47511?
To fix CVE-2025-47511, upgrade Welcart e-Commerce to version 2.11.14 or later.
What is path traversal and how does it relate to CVE-2025-47511?
Path traversal is a vulnerability that allows attackers to access files outside the web application's root directory, which is the core issue in CVE-2025-47511.