Description
WordPress Plugin Welcart e-Commerce is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Welcart e-Commerce version 2.2.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.8 or latest
References
https://blog.nintechnet.com/wordpress-welcart-e-commerce-plugin-fixed-vulnerabilities/
https://plugins.svn.wordpress.org/usc-e-shop/trunk/readme.txt
Related Vulnerabilities
Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.33)
IBM RTC Improper Privilege Management Vulnerability (CVE-2021-29774)
WordPress Plugin Platinum SEO Pack Cross-Site Scripting (1.3.7)
WordPress Plugin Wordfence Security-Firewall & Malware Scan Unspecified Vulnerability (5.3.2)
WordPress Plugin Task Manager Pro Multiple Vulnerabilities (1.3.1)