Skip to main content

Threat intelligence

Welcart e-Commerce <= 2.11.13 - Authenticated (Editor+) Arbitrary File Deletion

CVE-2025-47511 · usc-e-shop

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Usc E Shop at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Welcart e-Commerce <= 2.11.13 - Authenticated (Editor+) Arbitrary File Deletion
Affected software
usc-e-shop(Plugin)
Affected versions
  • ≤ 2.11.13
Authentication
Authenticated (see advisory title)
Vulnerability type
Other
Published
3 June 2025
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory 3f8f8319-d75f-4e71-90d4-1c60b5a8df90). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Usc E Shop version against this catalog when the Defence plugin is connected to your WordPress site.