What is CVE-2026-16066?
This vulnerability in the Welcart e-Commerce WordPress plugin (versions before 2.11.34) allows users with Author role and above to inject arbitrary web scripts via an unsanitized product field, leading to stored XSS. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: Welcart e-Commerce WordPress plaginində aşkarlanan bu zəiflik (XSS) 2.11.34-dən əvvəlki versiyalara təsir edir. Author və yuxarı roluna malik istifadəçilər məhsul səhifəsindəki təmizlənməmiş sahə vasitəsilə zərərli skript yeridə bilər. Plagini dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Welcart e-Commerce plugin are affected by CVE-2026-16066?
This stored XSS vulnerability affects versions of the Welcart e-Commerce WordPress plugin prior to 2.11.34.
What user role is required for an attacker to exploit CVE-2026-16066?
An attacker must have at least an Author role, or a higher privileged role, on the WordPress site to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.