← WordPress Vulnerabilities
WordPress security by component

Welcart e-Commerce

Welcart e-Commerce adds ecommerce functionality for managing products, catalogs, shopping carts, customer orders, and payments in WordPress.

Welcart e-Commerce (usc-e-shop) is a WordPress plugin with 18 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 8.8.

Plugin slug: usc-e-shop

CVE-2026-19887: Welcart permits unauthenticated object injection through its Telecom EDY callback

Welcart through 2.12.1 lets an unauthenticated buyer store arbitrary reserve metadata during checkout, then select and unserialize it through the usces_action_acting_transaction Telecom EDY callback without provider, transaction, source-address, or ownership validation. Its bundled TCPDF library supplies a POP chain for arbitrary file deletion; when an administrator prints an invoice, deletion of wp-config.php can enable site reinstallation and code execution.

PublishedSep 05, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for usc-e-shop
Safe version
Sep 05, 2026 CVE-2026-19887
Welcart permits unauthenticated object injection through its Telecom EDY callback
Welcart through 2.12.1 lets an unauthenticated buyer store arbitrary reserve metadata during checkout, then select and unserialize it through the usces_action_acting_transaction Telecom EDY callback without provider, transaction, source-address, or ownership validation. Its bundled TCPDF library supplies a POP chain for arbitrary file deletion; when an administrator prints an invoice, deletion of wp-config.php can enable site reinstallation and code execution.
See mitigation notes
CVE8.8
NVDPending
Sep 01, 2026 CVE-2026-19914
Welcart guest checkout permits stored cross-site scripting against administrators
Welcart e-Commerce through 2.12.1 insufficiently sanitizes and escapes the custom_order value submitted through guest checkout. An unauthenticated attacker can store script in an order, and the payload executes when an administrator views that order in WordPress administration.
See mitigation notes
CVE7.2
NVDPending
Aug 21, 2026 CVE-2025-15671
Welcart e-Commerce permits unauthenticated customer session fixation
Welcart e-Commerce before 2.12.1 accepts a session identifier from an attacker-controlled request parameter and does not regenerate that identifier when the customer authenticates. An unauthenticated attacker can send a victim a crafted login request that fixes the shop session, then reuse the known identifier after the victim signs in to take over the customer's account.
2.12.1
CVE5.4
NVDPending
Aug 13, 2026 CVE-2026-27539
Welcart e-Commerce: Cross-site scripting
Welcart e-Commerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.11.31.
2.11.32
CVE7.1
NVDPending
Aug 12, 2026 CVE-2026-15213
Welcart settlement callbacks permit payment-notification spoofing
Welcart e-Commerce before 2.11.33 accepts unauthenticated convenience-store and bank-transfer settlement notifications without proving they came from the payment provider. In the representative Epsilon path, EPSILON_SETTLEMENT::acting_transaction() accepts POST trans_code, user_id, order_number and paid; paid=1 resolves the attacker-supplied order through its stored settlement ID and passes it to usces_change_order_receipt() as receipted. An attacker who knows their own unpaid order number can therefore mark it paid and potentially obtain fulfilment without payment. Version 2.11.33 adds source-origin validation to provider notification paths. The reporter's exact targeted provider remains undisclosed until August 24.
2.11.33
CVE5.3
NVDPending
Aug 12, 2026 CVE-2026-16066
Welcart product field permits Author stored XSS
Welcart e-Commerce before 2.11.34 lets an Author store script-bearing content in the product-name field exposed as itemName and getItemName(). Multiple product-facing output paths render the stored name without contextual escaping, so a visitor viewing the affected product executes the script. Version 2.11.34 applies esc_html(), esc_attr() and esc_js() at the remaining product-name sinks. The exact editor POST parameter and reporter's specific page template are not disclosed.
2.11.34
CVE5.4
NVDPending
Jun 15, 2026 CVE-2026-49775
Welcart e-Commerce: Broken access control
Welcart e-Commerce is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.11.28.
2.11.29
CVE6.5
NVDPending
Oct 27, 2025 CVE-2025-62953
Welcart e-Commerce: A security weakness
Welcart e-Commerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Sep 10, 2025 CVE-2025-9367
Welcart e-Commerce: Cross-site scripting
Welcart e-Commerce is affected by cross-site scripting. Exploitation requires an authenticated editor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVDPending
Sep 09, 2025 CVE-2025-58984
Welcart e-Commerce: Cross-site scripting
Welcart e-Commerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Aug 20, 2025 CVE-2025-54012
Welcart e-Commerce: Code execution
Welcart e-Commerce is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVDPending
Jul 16, 2025 CVE-2025-54013
Welcart e-Commerce: Cross-site scripting
Welcart e-Commerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Feb 12, 2025 CVE-2025-0511
Welcart e-Commerce: Cross-site scripting
Welcart e-Commerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Jun 11, 2024 CVE-2024-32144
Welcart e-Commerce: A security weakness
Welcart e-Commerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Dec 28, 2023 CVE-2023-50847
Welcart e-Commerce: SQL injection
Welcart e-Commerce is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Mar 29, 2023 CVE-2023-22705
Usc E Shop: Cross-site scripting
Usc E Shop is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Nov 18, 2022 CVE-2022-41840
Usc E Shop: Filesystem traversal
Usc E Shop is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVD9.8
Nov 07, 2020 CVE-2020-28339
Usc E Shop: A security weakness
Usc E Shop is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD8.8