Impact
The vulnerability lies in the Welcart e‑Commerce WordPress plugin in versions prior to 2.11.32, where a value imported from a CSV file is not properly sanitized before being embedded in a SQL query. This flaw enables an attacker with Editor level access or higher—including any custom shop‑management roles—to inject arbitrary SQL statements, leading to unauthorized data read, modification, or deletion.
Affected Systems
Any WordPress site running the Welcart e‑Commerce plugin before 2.11.32 is affected. Users assigned the Editor role or any role that inherits Editor permissions, as well as custom shop‑management roles defined by the plugin, can exploit the flaw during the CSV import process.
Risk and Exploitability
The exploit requires the attacker to have Editor‑level access to the site and to upload a specially crafted CSV file. The attack vector is the CSV import functionality, which is authenticated and role‑restricted. No public exploits are listed in KEV, and the EPSS score is < 1%. The CVSS score of 6.5 reflects a moderate severity, but the potential impact is high due to direct database access. With the ability to execute arbitrary SQL, an attacker could exfiltrate merchant data, alter orders, or disrupt the e‑commerce operation.
OpenCVE Enrichment