HIGH
uscnanbu
CVE published 2026-09-05
CVE-2026-19887
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection due to deserialization of untrusted input in the Telecom EDY payment callback. This allows unauthenticated attackers to store arbitrary 'reserve' key/value pairs as order metadata and then unserialize them without any checks, potentially leading to file deletion and remote code execution.