PatchSiren

Welcart CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Welcart CVE published 2026-08-06

CVE-2026-16065

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitize a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above to perform SQL injection attacks. This vulnerability has a medium severity with a CVSS score of 6.5. The CVE record was published on 2026-08-06T07:16:28.197Z and has not been modified since then. Affected [truncated]