Cross-Site Scripting Vulnerabilities in Welcart Plugin for WordPress
CVE-2015-2973
Currently unrated
Summary
The Welcart plugin for WordPress is susceptible to multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML through the 'usces_referer' parameter in various PHP files, potentially leading to unauthorized actions or data exposure. This can be exploited through specific forms, including admin-related functions, severely impacting the integrity and security of the affected WordPress sites.
References
Timeline
Vulnerability published
Vulnerability Reserved