Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51979 | The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack. |
Fri, 04 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Feb 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Welcart
Welcart welcart E-commerce |
|
| CPEs | cpe:2.3:a:welcart:welcart_e-commerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Collne
Collne welcart E-commerce |
Welcart
Welcart welcart E-commerce |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-04T18:10:49.090Z
Reserved: 2022-12-22T10:09:37.443Z
Link: CVE-2022-4655
Updated: 2024-08-03T01:48:39.582Z
Status : Modified
Published: 2023-01-16T16:15:13.707
Modified: 2025-04-04T19:15:44.110
Link: CVE-2022-4655
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD