The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog
| Software | From | Fixed in |
|---|---|---|
| welcart / welcart_e-commerce | - | 2.9.5 |