Multiple SQL injection vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) changeSort or (2) switch parameter in the uscesitemedit page to wp-admin/admin.php.
Multiple cross-site scripting (XSS) vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote attackers to inject arbitrary web script or HTML via (1) unspecified vectors related to purchaselimit or the (2) name, (3) intl, (4) nocod, or (5) time parameter in an adddeliverymethod action to wp-admin/admin-ajax.php.