Welcart e-Commerce <= 2.11.20 - Authenticated (Editor+) Stored Cross-Site Scripting
Welcart e-Commerce
Minimum safe version
2.11.25
Update to 2.11.25 or later to address 64 fixable vulnerabilities
CVE-2025-12979
CVE-2025-62953
CVE-2025-10651
CVE-2025-10649
CVE-2025-58984
CVE-2025-54012
CVE-2025-54013
CVE-2025-47511
WordPress plugin "Welcart e-Commerce" vulnerable to untrusted data deserialization
WordPress Welcart e-Commerce Plugin <= 2.11.9 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-45366
CVE-2024-42404
Welcart e-Commerce < 2.9.6 - Admin+ PHP Object Injection
Welcart e-Commerce < 2.9.5 - Cross-Site Request Forgery
CVE-2024-32144
WordPress Welcart e-Commerce Plugin <= 2.9.3 is vulnerable to SQL Injection
WordPress Welcart e-Commerce Plugin <= 2.9.6 is vulnerable to Path Traversal
CVE-2023-5953
CVE-2023-5951
CVE-2023-5952
WordPress Welcart e-Commerce Plugin < 2.9.6 is vulnerable to PHP Object Injection
WordPress Welcart e-Commerce Plugin <= 2.9.4 is vulnerable to Arbitrary File Upload
Welcart e-Commerce <= 2.9.5 - Authenticated (Administrator+) PHP Object Injection
Welcart e-Commerce <= 2.9.4 - Authenticated (Subscriber+) Arbitrary File Upload
Welcart e-Commerce <= 2.9.4 - Cross-Site Request Forgery
CVE-2023-40219
WordPress Welcart e-Commerce Plugin < 2.8.22 is vulnerable to SQL Injection
Welcart e-Commerce <= 2.8.21 - Authenticated(level_5+) SQL Injection via get_logs
CVE-2021-4375
CVE-2021-4355
WordPress plugin "Welcart e-Commerce" vulnerable to directory traversal
CVE-2023-22705
CVE-2022-4655
Welcart e-Commerce 1.3.12 - DOM Cross-Site Scripting (XSS)
wpscan.com
Welcart e-Commerce < 2.1.1 - Authenticated SQL Injection
Welcart e-Commerce < 2.2.8 - Unauthenticated Information Disclosure
Welcart e-Commerce < 2.2.8 - Authenticated System Information Disclosure
Welcart e-Commerce <= 2.1.0 - SQL Injection
Welcart e-Commerce < 2.2.8 - Missing Capabilities Check to Information Disclosure
Welcart e-Commerce < 2.2.8 - Missing Capabilities Check to Information Disclosure
Welcart e-Commerce <= 2.8.3 - Cross-Site Request Forgery
Welcart e-Commerce <= 2.8.3 - Cross-Site Request Forgery
WordPress Welcart e-Commerce Plugin < 2.8.5 is vulnerable to Path Traversal
WordPress Welcart e-Commerce Plugin < 2.8.5 is vulnerable to Arbitrary File Download
WordPress Welcart e-Commerce Plugin < 2.8.5 is vulnerable to Deserialization of untrusted data
CVE-2022-3935
CVE-2022-3946
CVE-2022-41840
WordPress Welcart E-Commerce Plugin - Multiple Vulnerabilities
WordPress Welcart e-Commerce plugin <= 2.0.0 - SQL injection (SQLi) vulnerability
WordPress Welcart e-Commerce plugin <= 2.2.7 - Authenticated System Information Disclosure vulnerability
WordPress Welcart e-Commerce plugin <= 2.2.7 - Unauthenticated Information Disclosure vulnerability
CVE-2021-20734
CVE-2012-5178
CVE-2012-5177
Welcart vulnerable to SQL injection
CVE-2014-10016
CVE-2015-2973
CVE-2015-7791
CVE-2016-4827
CVE-2016-4828
CVE-2016-4826
CVE-2016-4825
CVE-2020-28339