Input validation vulnerability in Welcart e-Commerce 2.9.4

The Welcart e-Commerce plugin for WordPress is not secure in any version up to 2.9.4. It is possible for unauthenticated attackers to inject a foreign object into the plugin using a cookie. This could potentially cause damage, such as deleting important files, retrieving private information, or even running malicious code. It is not known if any other plugins or themes installed on the system would make this worse, but it is a possibility.

Detected in:

Welcart e-Commerce open vulnerable versions: >= * <= 2.9.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.