CVE-2026-16065: Unknown Welcart E-Commerce

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.

Affected products

  • Unknown Welcart E-Commerce: before 2.11.32 (fixed in 2.11.32)

Published 2026-08-06. Last modified 2026-08-26.