PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16065 Welcart CVE debrief

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitize a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above to perform SQL injection attacks. This vulnerability has a medium severity with a CVSS score of 6.5. The CVE record was published on 2026-08-06T07:16:28.197Z and has not been modified since then. Affected users should review and update the plugin to version 2.11.32 or later to prevent potential SQL injection attacks. The Editor role and above, including custom shop-management roles, are impacted. Evidence from WPScan indicates potential SQL injection vulnerability in Welcart e-Commerce WordPress plugin before version 2.11.32.

Vendor
Welcart
Product
Welcart e-Commerce WordPress plugin
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

Users of Welcart e-Commerce WordPress plugin, especially those with Editor role and above, should review and update the plugin to version 2.11.32 or later to prevent potential SQL injection attacks. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the vulnerability and implement necessary mitigations.

Technical summary

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitize a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above to perform SQL injection attacks. This vulnerability is due to insufficient sanitization of user input from an imported CSV file. The plugin's failure to properly validate and sanitize user input allows attackers to inject malicious SQL code. Users with the Editor role and above, including custom shop-management roles, can exploit this vulnerability. WPScan has provided details on the vulnerability, and defenders should verify the affected scope and review the plugin usage. The vulnerability has a CVSS score of 6.5 and is classified as medium severity.

Defensive priority

Medium-priority defensive review recommended due to potential SQL injection vulnerability in Welcart e-Commerce WordPress plugin.

Recommended defensive actions

  • Review and update Welcart e-Commerce WordPress plugin to version 2.11.32 or later
  • Restrict Editor role and above to minimize potential attack surface
  • Monitor plugin usage and update logs for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitize a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above to perform SQL injection attacks. Evidence from WPScan indicates potential SQL injection vulnerability in Welcart e-Commerce WordPress plugin before version 2.11.32. Users with Editor role and above can exploit this vulnerability. WPScan has provided details on the vulnerability, and defenders should verify the affected scope and review the plugin usage.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:28.197Z and has not been modified since then.