What is CVE-2026-15213?
The Welcart e-Commerce WordPress plugin before version 2.11.33 fails to verify the authenticity of its settlement callback, allowing an unauthenticated request to flip an order from unpaid to settled using only an order number and a status flag without any signature or amount validation. Affected sites should immediately update the plugin and restrict access to the callback endpoint.
Azərbaycanca: Welcart e-Commerce WordPress plugin-inin 2.11.33-dən əvvəlki versiyalarında autentifikasiya yoxlanışı olmayan callback funksiyası mövcuddur: autentifikasiya olunmamış sorğu yalnız sifariş nömrəsi və status bayrağı ilə ödənişi saxta şəkildə tamamlanmış kimi göstərə bilər. Təsirə məruz qalan saytlar dərhal plugin-i yeniləməli və callback endpoint-lərini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
How is the CVE-2026-15213 vulnerability in the Welcart e-Commerce plugin exploited?
The vulnerability occurs because the plugin's settlement callback function lacks authentication verification. An unauthenticated attacker can flip an order from unpaid to settled using only an order number and a status flag via a forged request.
What measures should be taken to protect against CVE-2026-15213?
Affected sites should immediately update the Welcart e-Commerce plugin to version 2.11.33 or later and restrict access to the callback endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.