CVE-2023-5952

CVE-2023-5952: Welcart e-Commerce < 2.9.5 - Unauthenticated PHP Object Injection

Vendor Unknown
Product Welcart e-Commerce
Published December 4, 2023
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog

Key dates

02Disclosure timeline

December 4, 2023 CVE published
August 2, 2024 Record updated