Description
The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because these are pay-later methods, an attacker can mark their own unpaid order as settled and obtain fulfilment without paying.
Published: 2026-08-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Welcart e‑Commerce WordPress plugin permits an unauthenticated user to forge a settlement callback. By sending a crafted request containing an order number and a status flag, a malicious actor can switch an order from unpaid to settled without any signature, amount verification, or origin check. This flaw allows an attacker to trigger fulfillment for orders they have not paid for, leading to financial loss and inventory mismanagement.

Affected Systems

All installations of the Welcart e‑Commerce plugin with a version earlier than 2.11.33. The vulnerability is present in any site that has not applied the latest plugin update. No specific vendor or product version list beyond the version threshold.

Risk and Exploitability

The CVSS score of 5.3 denotes moderate impact, and the EPSS score is not available, indicating insufficient data on exploit likelihood. The vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered via unauthenticated HTTP requests to the settlement callback endpoint, an attacker only needs to know a valid order number and can manipulate the status flag without authentication, making exploitation straightforward. Attacks could occur from any location that can reach the WordPress site, and there are no known mitigations beyond patching.

Generated by OpenCVE AI on August 13, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Welcart e-Commerce to version 2.11.33 or later
  • If an immediate update is not possible, restrict the settlement callback endpoint to authenticated or whitelisted IPs to prevent unauthenticated requests
  • Review recent orders and monitor for unexpected fulfillment of unpaid orders

Generated by OpenCVE AI on August 13, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Welcart
Welcart welcart E-commerce
Wordpress
Wordpress wordpress
Vendors & Products Welcart
Welcart welcart E-commerce
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
CWE-640

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because these are pay-later methods, an attacker can mark their own unpaid order as settled and obtain fulfilment without paying.
Title Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callback
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Welcart Welcart E-commerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T12:15:36.791Z

Reserved: 2026-07-09T07:43:54.525Z

Link: CVE-2026-15213

cve-icon Vulnrichment

Updated: 2026-08-12T12:15:31.918Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T12:17:46.690

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-15213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:30:21Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password