MEDIUM
CVE-2026-49775
CVSS
6.5
Description
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
Summary dbcve.org
This is an unauthenticated broken access control vulnerability in the Welcart e-Commerce WordPress plugin versions 2.11.28 and prior. An attacker without any credentials can access functionality that should require authentication or proper authorization, potentially allowing unauthorized administrative or data access operations.
Mitigation
Update Welcart e-Commerce to the latest version newer than 2.11.28. If immediate patching is not possible, restrict access to the affected plugin endpoints via web server configuration or disable the plugin until an update can be applied.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.19%
Probability of exploitation in next 30 days
9th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.