CVE-2021-4375
Last modified
CVE-2021-4375 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated attackers to download information including WordPress settings, plugin settings, PHP settings and server settings.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated attackers to download information including WordPress settings, plugin settings, PHP settings and server settings.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Welcart | Welcart E-Commerce | <= 2.2.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-4375?
How severe is CVE-2021-4375?
How do I fix CVE-2021-4375?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-43742CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via…5.4
- CVE-2021-43745A Denial of Service vulnerabilty exists in Trilium Notes 0.4…5.5
- CVE-2021-43746Adobe Premiere Rush versions 1.5.16 (and earlier) allows acc…5.5
- CVE-2021-43747Adobe Premiere Rush version 1.5.16 (and earlier) is affected…7.8
- CVE-2021-43748Adobe Premiere Rush versions 1.5.16 (and earlier) are affect…5.5
- CVE-2021-43749Adobe Premiere Rush versions 1.5.16 (and earlier) are affect…5.5
- CVE-2021-43750Adobe Premiere Rush versions 1.5.16 (and earlier) are affect…5.5
- CVE-2021-43751Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (a…3.3
- CVE-2021-43752Adobe Illustrator versions 25.4.2 (and earlier) and 26.0.1 (…5.5
- CVE-2021-43753Adobe Lightroom versions 4.4 (and earlier) are affected by a…7.8
- CVE-2021-43754Adobe Prelude version 22.1.1 (and earlier) is affected by an…7.8
- CVE-2021-43755Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (…7.8
Are you affected by CVE-2021-4375?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
