CVE-2022-4655: Welcart E-Commerce
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.
Affected products
- Welcart Welcart E-Commerce: before 2.8.9 (fixed in 2.8.9)
Published 2023-01-16. Last modified 2026-06-17.