S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-4140 Scanner

CVE-2022-4140 scanner - Arbitrary File Access vulnerability in WordPress Welcart e-Commerce

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-4140
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Welcart e-Commerce
AFFECTED< 2.8.5SAFE ✓≥ 2.8.5
Updated Aug 22, 2026View on NVD →
Detail

WordPress Welcart e-Commerce is a comprehensive plugin designed for building and managing online stores within the WordPress ecosystem. It provides a wide range of e-commerce functionalities, including product management, shopping cart, checkout processes, and payment gateway integrations. Developed by Collne Inc., this plugin is widely adopted by online retailers looking to leverage WordPress for their e-commerce platforms, offering a user-friendly interface and extensive customization options to meet diverse business needs.

The Arbitrary File Access vulnerability in versions of the WordPress Welcart e-Commerce plugin prior to 2.8.5 allows attackers to read arbitrary files on the server. This flaw is due to inadequate validation of user inputs, specifically the 'logfile' parameter, which can be manipulated to fetch sensitive files from the server, leading to information disclosure.

Exploitation involves an attacker crafting a malicious URL that targets the 'content-log.php' file, utilizing the 'logfile' parameter to specify the path of the file they wish to access. This vulnerability does not require authentication, making it possible for any remote attacker to retrieve contents of sensitive files such as /etc/passwd or /Windows/win.ini, depending on the server's operating system. The access to such files can disclose critical information that could be used to further compromise the server.

Successful exploitation could result in unauthorized access to sensitive information stored on the server, including but not limited to user credentials, configuration details, and potentially encrypted data. This exposure can lead to further attacks, including but not limited to data manipulation, persistent access, or lateral movement within the network infrastructure, posing a significant risk to the security of the WordPress site and its underlying server.

S4E provides an invaluable service for detecting and mitigating vulnerabilities like the Arbitrary File Access in WordPress Welcart e-Commerce. By subscribing to our platform, users benefit from thorough vulnerability scans, real-time monitoring, and expert remediation advice. This proactive approach to cybersecurity ensures that your digital assets are protected against emerging threats, maintaining the integrity and trustworthiness of your online presence.

 

References

Solution Advice
  1. Immediately update the WordPress Welcart e-Commerce plugin to version 2.8.5 or higher, as this version addresses the vulnerability.
  2. Regularly update all WordPress plugins, themes, and core software to their latest versions to mitigate known vulnerabilities.
  3. Implement file access controls and restrictions on the server to limit the files that can be accessed through web applications.
  4. Conduct regular security audits of your WordPress site and associated plugins to identify and rectify potential vulnerabilities.
  5. Consider using a web application firewall (WAF) to detect and block malicious requests attempting to exploit vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-4140 scanner - Arbitrary File Access vulnerability in WordPress Welcart e-Commerce | S4E