Welcart E Commerce

WordPress plugin · welcart-e-commerce · WordPress.org ↗
0
Critical
0
High
4
Known total
0
Unfixed
Running Welcart E Commerce on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
MEDIUM
CVSS 5.4
Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter
CVE.org
>=0, <2.12.1 v2.12.1 CVE-2025-15671 Aug 21, 2026
MEDIUM
CVSS 5.3
Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callback
CVE.org
>=0, <2.11.33 v2.11.33 CVE-2026-15213 Aug 12, 2026
MEDIUM
CVSS 5.4
Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name
CVE.org
>=0, <2.11.34 v2.11.34 CVE-2026-16066 Aug 12, 2026
MEDIUM
CVSS 6.5
Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import
CVE.org
>=0, <2.11.32 v2.11.32 CVE-2026-16065 Aug 6, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.