Vulnerabilities > CVE-2021-4355 - Missing Authorization vulnerability in Collne Welcart E-Commerce

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
collne
CWE-862

Summary

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to download lists of members, products and orders.

Vulnerable Configurations

Part Description Count
Application
Collne
164

Common Weakness Enumeration (CWE)