The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 10 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Feb 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Welcart
Welcart welcart E-commerce |
|
| CPEs | cpe:2.3:a:welcart:welcart_e-commerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Collne
Collne welcart E-commerce |
Welcart
Welcart welcart E-commerce |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-10T19:11:34.151Z
Reserved: 2022-11-25T09:56:19.096Z
Link: CVE-2022-4140
Updated: 2024-08-03T01:27:54.492Z
Status : Modified
Published: 2023-01-02T22:15:16.287
Modified: 2025-04-10T19:15:51.080
Link: CVE-2022-4140
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.