Welcart e-Commerce
Welcart e-Commerce adds ecommerce functionality for managing products, catalogs, shopping carts, customer orders, and payments in WordPress.
Welcart e-Commerce (usc-e-shop) is a WordPress plugin with 18 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 8.8.
usc-e-shopCVE-2026-19887: Welcart permits unauthenticated object injection through its Telecom EDY callback
Welcart through 2.12.1 lets an unauthenticated buyer store arbitrary reserve metadata during checkout, then select and unserialize it through the usces_action_acting_transaction Telecom EDY callback without provider, transaction, source-address, or ownership validation. Its bundled TCPDF library supplies a POP chain for arbitrary file deletion; when an administrator prints an invoice, deletion of wp-config.php can enable site reinstallation and code execution.
| Safe version |
|
||
|---|---|---|---|
| Sep 05, 2026 |
CVE-2026-19887
Welcart permits unauthenticated object injection through its Telecom EDY callback
Welcart through 2.12.1 lets an unauthenticated buyer store arbitrary reserve metadata during checkout, then select and unserialize it through the usces_action_acting_transaction Telecom EDY callback without provider, transaction, source-address, or ownership validation. Its bundled TCPDF library supplies a POP chain for arbitrary file deletion; when an administrator prints an invoice, deletion of wp-config.php can enable site reinstallation and code execution.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Sep 01, 2026 |
CVE-2026-19914
Welcart guest checkout permits stored cross-site scripting against administrators
Welcart e-Commerce through 2.12.1 insufficiently sanitizes and escapes the custom_order value submitted through guest checkout. An unauthenticated attacker can store script in an order, and the payload executes when an administrator views that order in WordPress administration.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Aug 21, 2026 |
CVE-2025-15671
Welcart e-Commerce permits unauthenticated customer session fixation
Welcart e-Commerce before 2.12.1 accepts a session identifier from an attacker-controlled request parameter and does not regenerate that identifier when the customer authenticates. An unauthenticated attacker can send a victim a crafted login request that fixes the shop session, then reuse the known identifier after the victim signs in to take over the customer's account.
|
2.12.1 |
CVE5.4
NVDPending
|
| Aug 13, 2026 |
CVE-2026-27539
Welcart e-Commerce: Cross-site scripting
Welcart e-Commerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.11.31.
|
2.11.32 |
CVE7.1
NVDPending
|
| Aug 12, 2026 |
CVE-2026-15213
Welcart settlement callbacks permit payment-notification spoofing
Welcart e-Commerce before 2.11.33 accepts unauthenticated convenience-store and bank-transfer settlement notifications without proving they came from the payment provider. In the representative Epsilon path, EPSILON_SETTLEMENT::acting_transaction() accepts POST trans_code, user_id, order_number and paid; paid=1 resolves the attacker-supplied order through its stored settlement ID and passes it to usces_change_order_receipt() as receipted. An attacker who knows their own unpaid order number can therefore mark it paid and potentially obtain fulfilment without payment. Version 2.11.33 adds source-origin validation to provider notification paths. The reporter's exact targeted provider remains undisclosed until August 24.
|
2.11.33 |
CVE5.3
NVDPending
|
| Aug 12, 2026 |
CVE-2026-16066
Welcart product field permits Author stored XSS
Welcart e-Commerce before 2.11.34 lets an Author store script-bearing content in the product-name field exposed as itemName and getItemName(). Multiple product-facing output paths render the stored name without contextual escaping, so a visitor viewing the affected product executes the script. Version 2.11.34 applies esc_html(), esc_attr() and esc_js() at the remaining product-name sinks. The exact editor POST parameter and reporter's specific page template are not disclosed.
|
2.11.34 |
CVE5.4
NVDPending
|
| Jun 15, 2026 |
CVE-2026-49775
Welcart e-Commerce: Broken access control
Welcart e-Commerce is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.11.28.
|
2.11.29 |
CVE6.5
NVDPending
|
| Oct 27, 2025 |
CVE-2025-62953
Welcart e-Commerce: A security weakness
Welcart e-Commerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 10, 2025 |
CVE-2025-9367
Welcart e-Commerce: Cross-site scripting
Welcart e-Commerce is affected by cross-site scripting. Exploitation requires an authenticated editor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVDPending
|
| Sep 09, 2025 |
CVE-2025-58984
Welcart e-Commerce: Cross-site scripting
Welcart e-Commerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Aug 20, 2025 |
CVE-2025-54012
Welcart e-Commerce: Code execution
Welcart e-Commerce is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Jul 16, 2025 |
CVE-2025-54013
Welcart e-Commerce: Cross-site scripting
Welcart e-Commerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Feb 12, 2025 |
CVE-2025-0511
Welcart e-Commerce: Cross-site scripting
Welcart e-Commerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Jun 11, 2024 |
CVE-2024-32144
Welcart e-Commerce: A security weakness
Welcart e-Commerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Dec 28, 2023 |
CVE-2023-50847
Welcart e-Commerce: SQL injection
Welcart e-Commerce is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Mar 29, 2023 |
CVE-2023-22705
Usc E Shop: Cross-site scripting
Usc E Shop is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Nov 18, 2022 |
CVE-2022-41840
Usc E Shop: Filesystem traversal
Usc E Shop is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVD9.8
|
| Nov 07, 2020 |
CVE-2020-28339
Usc E Shop: A security weakness
Usc E Shop is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD8.8
|