Input validation vulnerability in Welcart e-Commerce 2.9.4

The Welcart e-Commerce plugin for WordPress is vulnerable to a type of security attack called Reflected Cross-Site Scripting. This vulnerability affects all versions of the plugin from 2.9.4 and earlier. It is possible for unauthenticated attackers to inject malicious web scripts on pages that can be executed if a user is tricked into performing an action, such as clicking on a link. This happens because the plugin does not properly sanitize user input or properly escape output.

Detected in:

Welcart e-Commerce open vulnerable versions: >= * <= 2.9.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.