CVE-2025-27130

CVSS 3.0 Score 6.3 of 10 (medium)

Details

Published Apr 1, 2025
CWE ID 502

Summary

CVE-2025-27130 is a serious vulnerability affecting the Welcart e-Commerce platform version 2.11.6 and earlier. This issue involves untrusted data deserialization, which can allow a remote, unauthenticated attacker to execute arbitrary code. By accessing websites built using this product, an adversary can potentially exploit this vulnerability and gain unauthorized system control. This can lead to serious consequences, including data theft, unauthorized access, and system compromise. It is crucial that users of the Welcart e-Commerce platform update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Welcart E-commerce

Affected Vendors

  • Welcart