What is CVE-2026-16080?
A vulnerability, tracked as CVE-2026-16080, has been identified in the Image Uploader for Welcart plugin for WordPress. This is an SQL Injection issue via the 'post_title' parameter affecting all versions up to and including 1.4.6. Users are urged to update the plugin immediately or disable it until a patch is available.
Azərbaycanca: WordPress üçün Image Uploader for Welcart plaginində CVE-2026-16080 zəifliyi aşkarlanıb. Bu, 'post_title' parametri vasitəsilə baş verən SQL Injection zəifliyidir və 1.4.6 daxil olmaqla bütün versiyaları təsirləyir. Plaginin istifadəçiləri dərhal yeniləmə tətbiq etməli və ya müvəqqəti olaraq plagini deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: WordPress
FAQ2
Which versions of the Image Uploader for Welcart plugin are affected by CVE-2026-16080?
This SQL Injection vulnerability affects all plugin versions up to and including 1.4.6.
What is recommended to protect against CVE-2026-16080?
Users are urged to update the plugin immediately or temporarily disable it until a patch is available.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.