CVE-2026-15213: Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callback
The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because these are pay-later methods, an attacker can mark their own unpaid order as settled and obtain fulfilment without paying.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15213?
The severity of CVE-2026-15213 is medium with a score of 5.3.
How do I fix CVE-2026-15213?
To fix CVE-2026-15213, update the Welcart e-Commerce plugin to version 2.11.33 or later.
What is the main issue with CVE-2026-15213?
The main issue with CVE-2026-15213 is that it allows unauthenticated payment bypass via forged settlement callbacks.
What versions of the plugin are affected by CVE-2026-15213?
CVE-2026-15213 affects all versions of the Welcart e-Commerce plugin before 2.11.33.
How can an attacker exploit CVE-2026-15213?
An attacker can exploit CVE-2026-15213 by sending a forged request to change an order status from unpaid to settled using just the order number.