Object Injection Vulnerability in Collne Welcart e-Commerce Plugin for WordPress
CVE-2020-28339
8.8HIGH
Summary
The Collne Welcart e-Commerce plugin for WordPress contains a vulnerability that allows for object injection through the function usces_unserialize. This security flaw exists due to improper handling of serialized objects, which can lead to potential exploitation risks. Versions prior to 1.9.36 are affected. Users are advised to update to the latest version to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved