Input validation vulnerability in Welcart e-Commerce 2.8.22

The Welcart e-Commerce plugin for WordPress has a security vulnerability in versions up to and including 2.8.21. If someone with user level 5 or higher (which is roughly the same as an Author-level user) uses the ‘get_logs’ feature, they can add extra SQL queries which can be used to get sensitive information from the database. This happens because the user supplied parameters are not sufficiently escaped and the existing SQL query is not properly prepared.

Detected in:

Welcart e-Commerce open vulnerable versions: >= * < 2.8.22

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.