Welcart e-Commerce

Welcart e-Commerce has 55 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2026; 54 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.9, and the most serious one scores 9.8 out of 10. Severity breakdown: 3 critical and 23 high. 2023 was the busiest year with 11 disclosures.

The most common weakness is Cross-Site Scripting, behind 18 of the records (33%). Other recurring categories include SQL Injection, Deserialization Of Untrusted Data.

54 of the records (98%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2014.

35 independent researchers contributed these findings, most of them (4) reported by Gen Sato. Welcart e-Commerce is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891023.10.2009Today14.12.20126.1Welcart e-Commerce < 1.2.2 - Cross-Site Scripting CVSS 6.1 · 14.12.20128.8Welcart e-Commerce < 1.2.2 - Cross-Site Request Forgery CVSS 8.8 · 14.12.201203.03.20146.1Welcart e-Commerce <= 1.3.12 - Cross-Site Scripting CVSS 6.1 · 03.03.201404.03.20149.8Welcart e-Commerce <= 2.9.1 - SQL Injection CVSS 9.8 · 04.03.201415.07.20157.1Welcart e-Commerce < 1.4.18 - Multiple Cross-Site Scripting CVSS 7.1 · 15.07.201517.12.20158.8Welcart e-Commerce < 1.5.3 - SQL Injection CVSS 8.8 · 17.12.201524.06.20169.8Welcart e-Commerce <= 1.8.2 - Authentication Bypass CVSS 9.8 · 24.06.20166.1Welcart e-Commerce <= 1.8.2 - Cross-Site Scripting CVSS 6.1 · 24.06.20166.1Welcart e-Commerce < 1.8.3 - Reflected Cross-Site Scripting CVSS 6.1 · 24.06.20168.1Welcart e-Commerce < 1.8.3 - Object Injection CVSS 8.1 · 24.06.201605.11.20207.5Welcart e-Commerce <= 1.9.35 - PHP Object Injection CVSS 7.5 · 05.11.202008.02.20218.8Welcart e-Commerce <= 2.1.0 - SQL Injection CVSS 8.8 · 08.02.202111.06.20216.1Welcart e-Commerce <= 2.2.3 - Reflected Cross-Site Scripting CVSS 6.1 · 11.06.202106.08.20217.5Welcart e-Commerce < 2.2.8 - Missing Capabilities Check to Information Disclosure CVSS 7.5 · 06.08.20214.3Welcart e-Commerce < 2.2.8 - Missing Capabilities Check to Information Disclosure CVSS 4.3 · 06.08.202102.09.20227.5Welcart e-Commerce 2.6.0-2.7.7 - Information Disclosure via Arbitrary File Read CVSS 7.5 · 02.09.202216.11.20228.8Welcart e-Commerce <= 2.8.3 - Cross-Site Request Forgery CVSS 8.8 · 16.11.202221.11.20226.4Welcart e-Commerce <= 2.8.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 21.11.20225.4Welcart e-Commerce <= 2.8.3 - Missing Authorization CVSS 5.4 · 21.11.202228.11.20228.8Welcart e-Commerce <= 2.8.3 - Cross-Site Request Forgery CVSS 8.8 · 28.11.202230.11.20227.5Welcart e-Commerce 2.6.10-2.8.4 - Information Disclosure via Arbitrary File Read CVSS 7.5 · 30.11.202205.12.20226.5Welcart e-Commerce <= 2.8.4 - Authenticated (Subscriber+) Arbitrary File Read CVSS 6.5 · 05.12.20226.5Welcart e-Commerce <= 2.8.5 - Authenticated (Subscriber+) Information Disclosure and PHAR deserialization CVSS 6.5 · 05.12.202223.12.20226.4Welcart e-Commerce <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 23.12.202227.01.20237.2Welcart e-Commerce <= 2.8.10 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 27.01.202314.09.20238.8Welcart e-Commerce <= 2.8.21 - Authenticated(level_5+) SQL Injection via get_logs CVSS 8.8 · 14.09.20238.8Welcart e-Commerce <= 2.8.21 - Authenticated(Editor+) SQL Injection CVSS 8.8 · 14.09.202326.09.20238.8Welcart e-Commerce <= 2.8.21 - Authenticated(Editor+) Arbitrary File Upload CVSS 8.8 · 26.09.202310.11.20239.8Welcart e-Commerce <= 2.9.4 - Unauthenticated PHP Object Injection CVSS 9.8 · 10.11.20236.1Welcart e-Commerce <= 2.9.4 - Reflected Cross-Site Scripting CVSS 6.1 · 10.11.202314.11.20238.8Welcart e-Commerce <= 2.9.4 - Cross-Site Request Forgery CVSS 8.8 · 14.11.20238.8Welcart e-Commerce <= 2.9.4 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 14.11.202315.11.20237.2Welcart e-Commerce <= 2.9.5 - Authenticated (Administrator+) PHP Object Injection CVSS 7.2 · 15.11.202308.12.20234.1Welcart e-Commerce <= 2.9.6 - Authenticated (Administrator+) Directory Traversal CVSS 4.1 · 08.12.202321.12.20237.2Welcart e-Commerce <= 2.9.3 - Authenticated(Editor+) SQL Injection CVSS 7.2 · 21.12.202312.04.20245.4Welcart e-Commerce <= 2.9.14 - Missing Authorization CVSS 5.4 · 12.04.202418.09.20244.9Welcart e-Commerce <= 2.11.1 - Authenticated (Admin+) SQL Injection CVSS 4.9 · 18.09.202411.02.20257.2Welcart e-Commerce <= 2.11.9 - Unauthenticated Stored Cross-Site Scripting via name Parameter CVSS 7.2 · 11.02.202503.06.20256.5Welcart e-Commerce <= 2.11.13 - Authenticated (Editor+) Arbitrary File Deletion CVSS 6.5 · 03.06.202516.07.20255.5Welcart e-Commerce <= 2.11.16 - Authenticated (Editor+) Stored Cross-Site Scripting CVSS 5.5 · 16.07.202512.08.20256.6Welcart e-Commerce <= 2.11.16 - Authenticated (Editor+) PHP Object Injection CVSS 6.6 · 12.08.202509.09.20254.4Welcart e-Commerce <= 2.11.20 - Authenticated (Editor+) Stored Cross-Site Scripting CVSS 4.4 · 09.09.20255.5Welcart e-Commerce <= 2.11.20 - Authenticated (Editor+) Stored Cross-Site Scripting CVSS 5.5 · 09.09.202507.10.20256.5Welcart e-Commerce <= 2.11.21 - Authenticated (Author+) SQL Injection via Cookie CVSS 6.5 · 07.10.202514.10.20254.3Welcart e-Commerce <= 2.11.24 - Missing Authorization CVSS 4.3 · 14.10.202521.10.20255.5Welcart e-Commerce <= 2.11.22 - Authenticated (Editor+) Stored Cross-Site Scripting via order_mail CVSS 5.5 · 21.10.202512.11.20255.3Welcart e-Commerce <= 2.11.24 - Missing Authorization to Unauthenticated Information Exposure CVSS 5.3 · 12.11.202504.06.20265.3Welcart e-Commerce <= 2.11.28 - Missing Authorization CVSS 5.3 · 04.06.202631.07.20264.9Welcart e-Commerce <= 2.11.31 - Authenticated (Editor+) SQL Injection CVSS 4.9 · 31.07.202610.08.20266.4Welcart e-Commerce <= 2.11.33 - Authenticated (Author+) Stored Cross-Site Scripting CVSS 6.4 · 10.08.202611.08.20267.2Welcart e-Commerce <= 2.11.31 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 11.08.202614.08.20265.3Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass CVSS 5.3 · 14.08.202619.08.20266.5Welcart e-Commerce < 2.12.1 - Unauthenticated Session Fixation CVSS 6.5 · 19.08.202631.08.20267.2Welcart e-Commerce <= 2.12.1 - Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter CVSS 7.2 · 31.08.202604.09.20268.8Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback CVSS 8.8 · 04.09.2026

Strategic Overview

Avg CVSSMedium
6.9/ 10
Patch Coverage98%
Open

1

Fixed

54

Get automatic notifications for all Welcart e-Commerce vulnerabilities before they are exploited.

Most severe open issueCVSS 6.1CVE-2014-10016

Welcart e-Commerce <= 1.3.12 - Cross-Site Scripting

Read the full analysis

Vulnerability Records

55 records
2026-09-04 17:58CVE-2026-19887
8.8
High
darooYes
2026-08-31 20:54CVE-2026-19914
7.2
High
Afifudin MaarifYes
2026-08-19 00:00CVE-2025-15671
6.5
Medium
Maktoum (bRpsd)Yes
2026-08-14 00:00CVE-2026-15213
5.3
Medium
Pedro PinhoYes
2026-08-11 00:00CVE-2026-27539
7.2
High
K. SorrachatYes
2026-08-10 00:00CVE-2026-16066
6.4
Medium
Yaswanth Reddy SunkaraYes
2026-07-31 00:00CVE-2026-16065
4.9
Medium
Yaswanth Reddy SunkaraYes
2026-06-04 00:00CVE-2026-49775
5.3
Medium
dodoh4tYes
2025-11-12 00:00CVE-2025-12979
5.3
Medium
Marcin Dudek (dudekmar)Yes
2025-10-21 17:22CVE-2025-10651
5.5
Medium
Miguel SantarenoYes
Showing 1–10 of 55 reports
Welcart e-Commerce banner
Latestv2.12.3

Welcart e-Commerce

info@welcart

Author

info@welcart

4.5(6)
90/100
Last Updated
2026-09-11 (2d ago)
Active Installs
10,000+
Downloads
1,347,027
Requires WP
5.6+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2009-10-23 (17y ago)

Welcart is a free WordPress e-commerce plugin with the top market share in Japan. It offers extensive features and flexibility to help you build your own online store with ease. Compatible with PHP 7.4 to 8.3. SHOPPING CART SYSTEM Sell physical products with no limits on the number of items or categories. Manage inventory with SKU codes and configure flexible pricing and shipping options. Additional extension plugins are available to support digital content sales and subscriptions. Over 16 payment services can be added through the official Welcart website. Welcart Payment services (Japanese) DESIGN A free responsive theme (Welcart Basic) is available, along with premium themes. You can customize the design and layout however you like. Welcart Theme downloads (Japanese) MANAGING SYSTEM Order data is automatically saved and updated in the database. The order list page offers powerful filtering by customer information, date, product type, and more. From the order editing page, you can modify order details, send confirmation emails, download receipt PDFs, and more. MEMBERSHIP SYSTEM Welcart includes a built-in membership system with no additional plugins required. The member list page supports searching by customer information and purchase history. A point system is also available for members.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C