CyberRota Analysis
AI-GeneratedThe Welcart e-Commerce plugin for WordPress prior to version 2.11.32 is vulnerable to SQL injection due to inadequate sanitization of values imported from CSV files. This flaw allows users with Editor roles and above, including custom shop-management roles, to manipulate SQL queries, potentially compromising the database integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.