The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.
2023-01-16T16:15:13.707
2025-04-04T19:15:44.110
Modified
CVSSv3.1: 5.4 (MEDIUM)
-
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | welcart | welcart_e-commerce | < 2.8.9 | Yes |