CVE-2021-4355

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to download lists of members, products and orders.


We have discovered 1,155 live websites that are affected by CVE-2021-4355.

Run a Free Instant Scan




Affected Software

Product  Welcart
Category Ecommerce
Vulnerable Domains1,155 live websites (100% of Welcart install base)
Vulnerable Versions
  • from 0 through 2.2.8
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)



Details

  • Published - Jun 7, 2023
  • Updated - Dec 28, 2024

Credits

  • Jerome Bruandet (finder)

Website Distribution by Country

Number of websites using CVE-2021-4355
United States23 websites



Japan1,058 websites
Australia2 websites
Netherlands2 websites
Bulgaria1 websites
Spain1 websites
France1 websites
GB1 websites
Guatemala1 websites

Website Distribution by TLD

Number of websites using CVE-2021-4355
.com595 websites
.jp239 websites
.co.jp126 websites
.net94 websites
.org18 websites
.info15 websites
.be1 websites

Websites affected by CVE-2021-4355

Top websites that are affected by CVE-2021-4355. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com Japan***,***
***.**.jp Japan***,***
********.jp Japan***,***
******.net Japan***,***
*********.com Japan*,***,***
********.jp Japan*,***,***
*******.com Japan*,***,***
*******.com Japan*,***,***
*************.jp Japan*,***,***
**********.jp Japan*,***,***
See full domain list

FAQ

A total of 1,155 websites have been identified as vulnerable to CVE-2021-4355, based on global website indexing conducted by WebTechSurvey.
The Welcart is affected by the CVE-2021-4355 vulnerability.
Welcart versions up to 2.2.8 are vulnerable to CVE-2021-4355.
CVE-2021-4355 is resolved in version 2.2.8 of Welcart.