CVE-2016-4825

MEDIUM

Welcart E-commerce < 1.8.3 - Improper Input Validation

Title source: rule

Description

The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data.

Scores

CVSS v3 5.6
EPSS 0.0954
EPSS Percentile 92.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-20
Status draft

Affected Products (1)

welcart/welcart_e-commerce < 1.8.3

Timeline

Published Jun 25, 2016
Tracked Since Feb 18, 2026