Input validation vulnerability in Welcart e-Commerce 2.9.4

The Welcart e-Commerce plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This vulnerability affects all versions up to and including 2.9.4. It occurs because certain functions do not have the appropriate security measure, known as ‘nonce validation’, in place. This means that it is possible for an unauthorised person to send a fake request and, if the site administrator is tricked into clicking on the link, upload a file. Since the uploaded files are not checked in the correct way, this could lead to a malicious file being added to the system.

Detected in:

Welcart e-Commerce open vulnerable versions: >= * <= 2.9.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.