CVE-2022-41840

HIGH EXPLOITED NUCLEI

Welcart eCommerce <2.7.7 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-41840 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including PrinceAikinsBaidoo. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2022-41840, an unauthenticated file upload vulnerability in Zenario CMS <= 9.3. The exploit uploads a PHP webshell via a vulnerable AJAX endpoint and provides multiple execution options, including interactive webshell, single command execution, and reverse shell.

Description

Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.

Exploits (1)

nomisec WORKING POC
by PrinceAikinsBaidoo · poc
https://github.com/PrinceAikinsBaidoo/CVE-2022-41840-PoC

This repository contains a functional Python exploit for CVE-2022-41840, an unauthenticated file upload vulnerability in Zenario CMS <= 9.3. The exploit uploads a PHP webshell via a vulnerable AJAX endpoint and provides multiple execution options, including interactive webshell, single command execution, and reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zenario CMS <= 9.3
No auth needed
Prerequisites: Network access to the target Zenario CMS instance · Python 3.x with requests library
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

Welcart eCommerce <=2.7.7 - Local File Inclusion
CRITICALVERIFIEDby theamanrawat

Scores

CVSS v3 7.5
EPSS 0.0512
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2023-11-13
CWE
CWE-22
Status published
Products (2)
Collne Inc./Welcart e-Commerce (WordPress plugin) <= 2.7.7 - 2.7.7
welcart/welcart_e-commerce < 2.7.8
Published Nov 18, 2022
Tracked Since Feb 18, 2026