CVE-2016-4825
MEDIUMWelcart E-commerce < 1.8.3 - Improper Input Validation
Title source: ruleDescription
The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data.
Scores
CVSS v3
5.6
EPSS
0.0954
EPSS Percentile
92.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-20
Status
draft
Affected Products (1)
welcart/welcart_e-commerce
< 1.8.3
Timeline
Published
Jun 25, 2016
Tracked Since
Feb 18, 2026