Description
The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' action in all versions up to, and including, 2.11.24. This makes it possible for unauthenticated attackers to access configured payment credentials (ex. PayPal api secret) , as well as business contact details, mail templates, and other operational settings tied to the store.
Problem types
Product status
* (semver)
Timeline
| 2025-11-10: | Vendor Notified |
| 2025-11-12: | Disclosed |
Credits
Marcin Dudek
References
www.wordfence.com/...-2361-4d17-8d1b-9bdadcc69043?source=cve
plugins.trac.wordpress.org/...c-e-shop&sfp_email=&sfph_mail=