MEDIUM
fishpie
CVE published 2026-08-15
CVE-2026-16080
The Image Uploader for Welcart plugin for WordPress, specifically versions up to and including 1.4.6, is vulnerable to generic SQL Injection via the 'post_title' parameter. This vulnerability is due to insufficient escaping on the user-supplied parameter and a lack of sufficient preparation on the existing SQL query. As a result, authenticated attackers with author-level access and above can exploit this [truncated]