CVE-2026-16066 PUBLISHED

Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name

Assigner: WPScan
Reserved: 17.07.2026 Published: 12.08.2026 Updated: 12.08.2026

The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any visitor viewing the product page.

Product Status

Vendor Unknown
Product Welcart e-Commerce
Versions Default: unaffected
  • affected from 0 to 2.11.34 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE