CVE-2022-3946
EUVD-2022-4328012.12.2022, 18:15
The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| welcart | welcart_e-commerce | 𝑥 < 2.8.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration