CVE-2026-16066: Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name
The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any visitor viewing the product page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16066?
CVE-2026-16066 has a risk score of 48, indicating a moderate severity level.
How do I fix CVE-2026-16066?
To fix CVE-2026-16066, update the Welcart e-Commerce plugin to version 2.11.34 or later.
Who is affected by CVE-2026-16066?
CVE-2026-16066 affects users with the Author role and above who can create products in the Welcart e-Commerce plugin.
What type of vulnerability is CVE-2026-16066?
CVE-2026-16066 is a Stored Cross-Site Scripting (XSS) vulnerability.
What impact does CVE-2026-16066 have on website visitors?
CVE-2026-16066 can result in arbitrary web scripts being executed in the browsers of any visitors viewing the affected product pages.