CVE-2022-3946
12.12.2022, 18:15
The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.
| Vendor | Product | Version |
|---|---|---|
| welcart | welcart_e-commerce | 𝑥 < 2.8.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration