High severity8.8NVD Advisory· Published Apr 1, 2025· Updated Jun 17, 2026
CVE-2025-27130
CVE-2025-27130
Description
Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites created using the product.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:welcart:welcart_e-commerce:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:welcart:welcart_e-commerce:*:*:*:*:*:wordpress:*:*range: <=2.11.6
- (no CPE)range: <=2.11.6
- Welcart Inc./Welcart e-Commercev5Range: 2.11.6 and earlier versions
Patches
Vulnerability mechanics
References
2- jvn.jp/en/jp/JVN87266215/nvdThird Party Advisory
- www.welcart.com/archives/23868.htmlnvdRelease Notes
News mentions
0No linked articles in our index yet.