PT-2023-14110 · WordPress · Welcart E-Commerce

Published

2023-01-02

·

Updated

2025-04-10

·

CVE-2022-4236

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Welcart e-Commerce WordPress plugin versions prior to 2.8.5
Description The issue concerns the Welcart e-Commerce WordPress plugin, which does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users. This could allow users with a role as low as subscriber to read arbitrary files on the server.
Recommendations For versions prior to 2.8.5, update to version 2.8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action to prevent unauthorized file access.

Exploit

Fix

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2022-4236

Affected Products

Welcart E-Commerce