AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16065

MEDIUM · CVSS 6.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Welcart e-Commerce plugin for WordPress prior to version 2.11.32 is vulnerable to SQL injection due to inadequate sanitization of values imported from CSV files. This flaw allows users with Editor roles and above, including custom shop-management roles, to manipulate SQL queries, potentially compromising the database integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-16065
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%
WordPress

Original NVD Description

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.