VYPR

Welcart e-Commerce

by WordPress

CVEs (1)

  • CVE-2026-19887Sep 5, 2026
    risk 0.00cvss epss

    The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store…