Pricing
Case studies
Login
Start trial
Welcart e-Commerce
info@welcart
Developer
2.11.28
Latest version
10,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
29 patched
18 Mitigation rules
Authenticated (Editor+) Stored Cross-Site Scripting vulnerability
<= 2.11.20
31/12/2025
Missing Authorization to Unauthenticated Information Exposure vulnerability
<= 2.11.24
12/11/2025
Authenticated (Editor+) Stored Cross-Site Scripting via order_mail vulnerability
<= 2.11.22
21/10/2025
Broken Access Control vulnerability
<= 2.11.24
14/10/2025
Authenticated (Author+) SQL Injection via Cookie vulnerability
<= 2.11.21
08/10/2025
Cross Site Scripting (XSS) Vulnerability
<= 2.11.20
09/09/2025
PHP Object Injection Vulnerability
<= 2.11.16
12/08/2025
Cross Site Scripting (XSS) Vulnerability
<= 2.11.16
16/07/2025
Arbitrary File Deletion Vulnerability
<= 2.11.13
03/06/2025
Unauthenticated Stored Cross-Site Scripting via name Parameter vulnerability
<= 2.11.9
11/02/2025
Broken Access Control + CSRF vulnerability
<= 2.9.14
12/04/2024
SQL Injection vulnerability
<= 2.9.3
21/12/2023
Authenticated (Administrator+) Directory Traversal vulnerability
<= 2.9.6
11/12/2023
Authenticated (Administrator+) PHP Object Injection vulnerability
< 2.9.6
15/11/2023
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
<= 2.9.4
14/11/2023
Authenticated(level_5+) SQL Injection via get_logs vulnerability
< 2.8.22
15/09/2023
Cross Site Scripting (XSS) vulnerability
<= 2.8.10
27/01/2023
Contributor+ Stored XSS via Shortcode vulnerability
< 2.8.9
26/12/2022
Unauth. Arbitrary File Access vulnerability
< 2.8.5
05/12/2022
Auth. PHAR Deserialization vulnerability
< 2.8.5
05/12/2022
Auth. Arbitrary File Access vulnerability
< 2.8.5
05/12/2022
Auth. Arbitrary Shipping Method Creation/Update/Deletion vulnerability
<= 2.8.3
21/11/2022
Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilities
<= 2.8.3
21/11/2022
Unauth. Directory Traversal vulnerability
<= 2.7.7
20/10/2022
Unauthenticated Information Disclosure vulnerability
<= 2.2.7
06/08/2021
Authenticated System Information Disclosure vulnerability
<= 2.2.7
06/08/2021
Cross-Site Scripting (XSS) vulnerability
<= 2.2.3
11/06/2021
SQL injection (SQLi) vulnerability
<= 2.0.0
09/02/2021
Authenticated PHP Object Injection vulnerability
<= 1.9.35
05/11/2020