Description
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and including, 2.11.21 due to insufficient escaping on the user supplied value and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published: 2025-10-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exfiltration via SQL Injection
Action: Patch Now
AI Analysis

Impact

The Welcart e-Commerce plugin for WordPress contains a SQL Injection flaw that an attacker can exploit by manipulating a cookie. The insufficient escaping of user supplied values in the query construction allows the execution of arbitrary SQL statements. The associated weakness is CWE-89. An attacker with Author or higher privileges can craft a cookie to append malicious SQL that may read or modify sensitive database contents, leading to data theft or corruption. The attack vector is inferred from the description: the vulnerability is triggered by sending a crafted cookie in an authenticated web request, though the CVE entry does not explicitly state the transport mechanism.

Affected Systems

All installations of Welcart e-Commerce version 2.11.21 or earlier on WordPress sites. The plugin is distributed by the vendor uscnanbu. Users running these versions are susceptible; newer releases beyond 2.11.21 are not affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1% shows a very low probability of exploitation at this time, and it is not listed in the CISA KEV catalog. However, the vulnerability requires authenticated access with Author-level privileges, which many site administrators or content authors possess. Attackers can trigger the flaw by sending an HTTP request containing a crafted cookie; this inference is based on the description that manipulation occurs via a cookie. Thus the likely attack vector is an authenticated web request with a modified cookie. Given the limited scope of required privileges, the risk is moderate but could be severe if the attacker gains access to privileged accounts.

Generated by OpenCVE AI on April 22, 2026 at 14:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Welcart e-Commerce plugin to the latest version released after 2.11.21
  • Disable the plugin if it cannot be upgraded until a patch is applied
  • Ensure that all WordPress installations are running the latest core and plugin versions and enforce least privilege for author role accounts

Generated by OpenCVE AI on April 22, 2026 at 14:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Welcart
Welcart e-commerce
Welcart welcart
Welcart welcart E-commerce
Wordpress
Wordpress wordpress
Vendors & Products Welcart
Welcart e-commerce
Welcart welcart
Welcart welcart E-commerce
Wordpress
Wordpress wordpress

Wed, 08 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Oct 2025 11:30:00 +0000

Type Values Removed Values Added
Description The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and including, 2.11.21 due to insufficient escaping on the user supplied value and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Title Welcart e-Commerce <= 2.11.21 - Authenticated (Author+) SQL Injection via Cookie
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Welcart E-commerce Welcart Welcart E-commerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:51:26.852Z

Reserved: 2025-09-17T18:15:39.316Z

Link: CVE-2025-10649

cve-icon Vulnrichment

Updated: 2025-10-08T13:27:43.059Z

cve-icon NVD

Status : Deferred

Published: 2025-10-08T12:15:36.047

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-10649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T14:15:20Z

Weaknesses