MEDIUM

CVE-2026-49775

2026-06-15 CVSS v3.1
CVSS
6.5

Description

Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

Summary dbcve.org

This is an unauthenticated broken access control vulnerability in the Welcart e-Commerce WordPress plugin versions 2.11.28 and prior. An attacker without any credentials can access functionality that should require authentication or proper authorization, potentially allowing unauthorized administrative or data access operations.

Mitigation

Update Welcart e-Commerce to the latest version newer than 2.11.28. If immediate patching is not possible, restrict access to the affected plugin endpoints via web server configuration or disable the plugin until an update can be applied.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.19%
Probability of exploitation in next 30 days
9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE