CVE-2026-16065: Unknown Welcart E-Commerce
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.
Affected products
- Unknown Welcart E-Commerce: before 2.11.32 (fixed in 2.11.32)
Published 2026-08-06. Last modified 2026-08-26.