CVE-2016-4825

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
25/06/2016
Last modified:
12/04/2025

Description

The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:welcart:welcart_e-commerce:*:*:*:*:*:wordpress:*:* 1.8.3 (excluding)