CVE-2016-4825: Welcart E-Commerce

Medium severity, CVSS 5.6. EPSS: 2.9% chance of exploitation in the next 30 days.

The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data.

Affected products

  • Welcart Welcart E-Commerce: before 1.8.3 (fixed in 1.8.3)

Published 2016-06-25. Last modified 2026-06-17.