Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51594 | The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a role as low as subscriber to read arbitrary files on the server. |
Thu, 10 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Feb 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Welcart
Welcart welcart E-commerce |
|
| CPEs | cpe:2.3:a:welcart:welcart_e-commerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Collne
Collne welcart E-commerce |
Welcart
Welcart welcart E-commerce |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-10T18:47:32.231Z
Reserved: 2022-11-30T14:48:23.329Z
Link: CVE-2022-4236
Updated: 2024-08-03T01:34:49.922Z
Status : Modified
Published: 2023-01-02T22:15:16.567
Modified: 2025-04-10T19:15:51.700
Link: CVE-2022-4236
No data.
OpenCVE Enrichment
No data.
EUVD