What is CVE-2026-16065?
The Welcart e-Commerce WordPress plugin before version 2.11.32 fails to properly sanitize a value taken from an imported CSV file before using it in a SQL statement. This allows users with the Editor role and above, including custom shop-management roles, to perform SQL injection attacks. Upgrading the plugin to version 2.11.32 or later is recommended.
Azərbaycanca: Welcart e-Commerce WordPress plaginində 2.11.32 versiyasından əvvəl yüklənmiş CSV faylındakı verilənlərin SQL sorğusunda istifadə edilməzdən əvvəl düzgün təmizlənməməsi SQL injection zəifliyinə səbəb olur. Bu zəiflik Editor roluna və yuxarısına (xüsusi mağaza idarəetmə rolları daxil) malik istifadəçilərə SQL injection hücumları etməyə imkan verir. Plagini ən azı 2.11.32 versiyasına yeniləməyiniz tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the Welcart e-Commerce plugin are affected by the CVE-2026-16065 SQL injection vulnerability?
All versions before 2.11.32 are affected. Upgrading the plugin to version 2.11.32 or later is recommended.
What privilege level is required to exploit CVE-2026-16065?
This vulnerability requires the Editor role and above in WordPress, including custom shop-management roles.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.