Welcart e-Commerce Missing Authorization Vulnerability Allowing Unauthenticated Data Exposure

Vulnerability

A vulnerability exists in the Welcart e-Commerce plugin for WordPress, in all versions through 2.11.24, due to a missing capability check on the 'usces_export' action. This flaw allows unauthenticated attackers to access sensitive information, including payment credentials (such as PayPal API secrets), business contact details, mail templates, and other operational settings related to the store.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive business information and payment credentials.

Remediation

Users can update to version 2.11.25 or a newer patched version to address this vulnerability.

Added: Nov 13, 2025, 4:24 AM
Updated: Nov 13, 2025, 4:24 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
8.2
remediation
7.7
relevance
1.0
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.