Junglewise Threat Intelligence

CVE-2026-49775: Welcart e-Commerce broken access control in WordPress plugin

CVE-2026-49775 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Executive brief

Welcart e-Commerce is a popular WordPress plugin used to manage online stores and shopping carts. A security flaw in versions 2.11.28 and earlier allows unauthorized individuals to perform actions that should be restricted to administrators or registered users. This could lead to unauthorized changes to store settings or disruptions to the online shopping service.

Technical details

A broken access control vulnerability (CWE-862) exists in the Welcart e-Commerce plugin for WordPress due to missing authorization checks in certain functions. An unauthenticated remote attacker can exploit this flaw by sending crafted network requests to the affected site. Successful exploitation allows the attacker to execute actions that should require higher privileges, potentially impacting the integrity and availability of the store's configuration or data. The issue is resolved in version 2.11.29.

Affected products

  • Welcart Welcart e-Commerce <= 2.11.28

Timeline

  • 2026-05-23: other: Reported by researcher dodoh4t
  • 2026-06-04: advisory: Initial disclosure by Patchstack
  • 2026-06-15: disclosed: CVE published to NVD

References