Vulnerabilities > CVE-2021-4355 - Missing Authorization vulnerability in Welcart E-Commerce

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
welcart
CWE-862

Summary

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to download lists of members, products and orders.

Vulnerable Configurations

Part Description Count
Application
Welcart
164

Common Weakness Enumeration (CWE)