The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the upload_certificate_file function. This makes it possible for administrators to upload .pem or .crt files to arbitrary locations on the server.
2023-12-09T07:15:08.130
2025-02-20T18:34:50.990
Modified
CVSSv3.1: 4.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | welcart | welcart_e-commerce | < 2.9.7 | Yes |