Impact
The vulnerability is a missing authorization flaw in the Welcart e‑Commerce plugin for WordPress that allows an attacker to exploit incorrectly configured access control levels, giving unauthorized access to plugin-protected functionality.
Affected Systems
Vendors: Welcart e‑Commerce. Product: Welcart e‑Commerce plugin for WordPress. Affected versions: all releases up to and including 2.11.24.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate potential impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker likely would need to use the plugin’s administrative pages accessed through the WordPress web interface; because authorization checks are missing, a valid user session could be abused to reach restricted functionality.
OpenCVE Enrichment