PatchSiren

uscnanbu CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH uscnanbu CVE published 2026-09-05

CVE-2026-19887

The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection due to deserialization of untrusted input in the Telecom EDY payment callback. This allows unauthenticated attackers to store arbitrary 'reserve' key/value pairs as order metadata and then unserialize them without any checks, potentially leading to file deletion and remote code execution.