CVE-2026-16065: Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import
Published Aug 6, 2026
·Updated
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.
Affected Software
1 affected component
Welcart e-Commerce WordPress plugin<2.11.32
Event History
Aug 6, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16065?
CVE-2026-16065 has a risk rating of 50, indicating a medium level of severity.
2
How do I fix CVE-2026-16065?
To address CVE-2026-16065, update the Welcart e-Commerce plugin to version 2.11.32 or later.
3
Who is affected by CVE-2026-16065?
CVE-2026-16065 affects users with the Editor role and above in the Welcart e-Commerce plugin.
4
What type of vulnerability is CVE-2026-16065?
CVE-2026-16065 is classified as an SQL Injection vulnerability.
5
What can attackers do with CVE-2026-16065?
Attackers can exploit CVE-2026-16065 to execute unauthorized SQL commands leading to data leaks or corruption.