PatchSiren cyber security CVE debrief
CVE-2026-16065 Welcart CVE debrief
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitize a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above to perform SQL injection attacks. This vulnerability has a medium severity with a CVSS score of 6.5. The CVE record was published on 2026-08-06T07:16:28.197Z and has not been modified since then. Affected users should review and update the plugin to version 2.11.32 or later to prevent potential SQL injection attacks. The Editor role and above, including custom shop-management roles, are impacted. Evidence from WPScan indicates potential SQL injection vulnerability in Welcart e-Commerce WordPress plugin before version 2.11.32.
- Vendor
- Welcart
- Product
- Welcart e-Commerce WordPress plugin
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Users of Welcart e-Commerce WordPress plugin, especially those with Editor role and above, should review and update the plugin to version 2.11.32 or later to prevent potential SQL injection attacks. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the vulnerability and implement necessary mitigations.
Technical summary
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitize a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above to perform SQL injection attacks. This vulnerability is due to insufficient sanitization of user input from an imported CSV file. The plugin's failure to properly validate and sanitize user input allows attackers to inject malicious SQL code. Users with the Editor role and above, including custom shop-management roles, can exploit this vulnerability. WPScan has provided details on the vulnerability, and defenders should verify the affected scope and review the plugin usage. The vulnerability has a CVSS score of 6.5 and is classified as medium severity.
Defensive priority
Medium-priority defensive review recommended due to potential SQL injection vulnerability in Welcart e-Commerce WordPress plugin.
Recommended defensive actions
- Review and update Welcart e-Commerce WordPress plugin to version 2.11.32 or later
- Restrict Editor role and above to minimize potential attack surface
- Monitor plugin usage and update logs for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitize a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above to perform SQL injection attacks. Evidence from WPScan indicates potential SQL injection vulnerability in Welcart e-Commerce WordPress plugin before version 2.11.32. Users with Editor role and above can exploit this vulnerability. WPScan has provided details on the vulnerability, and defenders should verify the affected scope and review the plugin usage.
Official resources
-
CVE-2026-16065 CVE record
CVE.org
-
CVE-2026-16065 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:28.197Z and has not been modified since then.