The usc-e-shop (aka Collne Welcart e-Commerce) plugin...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Feb 20, 2025
Description
Published by the National Vulnerability Database
Nov 7, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Feb 20, 2025
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not a complete POP chain.
References