The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
2023-01-02T22:15:16.287
2025-04-10T19:15:51.080
Modified
CVSSv3.1: 7.5 (HIGH)
-
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | welcart | welcart_e-commerce | < 2.8.5 | Yes |