Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51595 | The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functions via various AJAX actions available to any authenticated users, which could allow users with a role as low as subscriber to perform PHAR deserialisation when they can upload a file and a suitable gadget chain is present on the blog |
Thu, 10 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Feb 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Welcart
Welcart welcart E-commerce |
|
| CPEs | cpe:2.3:a:welcart:welcart_e-commerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Collne
Collne welcart E-commerce |
Welcart
Welcart welcart E-commerce |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-10T18:35:37.520Z
Reserved: 2022-11-30T14:48:37.966Z
Link: CVE-2022-4237
Updated: 2024-08-03T01:34:49.984Z
Status : Modified
Published: 2023-01-02T22:15:16.630
Modified: 2025-04-10T19:15:51.863
Link: CVE-2022-4237
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD