Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-3946
HistoryDec 12, 2022 - 6:15 p.m.

Cross site request forgery (csrf)

2022-12-1218:15:00
PRIOn knowledge base
www.prio-n.com
3
welcart e-commerce
wordpress
csrf
ajax
shipping methods
authorization

0.001 Low

EPSS

Percentile

21.4%

The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.

CPENameOperatorVersion
welcart_e-commercelt2.8.4

0.001 Low

EPSS

Percentile

21.4%

Related for PRION:CVE-2022-3946