Welcart e-Commerce, CVE-2026-16065
- CVE, Research URL
- Home page URL
- Application
- Published on
- Aug 06, 2026
- Research Description
- The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.
- Affected versions
-
max 2.11.32.
- Status
-
vulnerable