PT-2026-86327 · WordPress+1 · Welcart E-Commerce+1

·

CVE-2026-19887

·

Published

2026-09-05

·

Updated

2026-09-06

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Welcart e-Commerce plugin for WordPress versions prior to 2.12.2
Description PHP Object Injection occurs due to the deserialization of untrusted input within the Telecom EDY payment callback usces action acting transaction(). Unauthenticated attackers can store arbitrary reserve key/value pairs as order metadata during a public checkout. By invoking the callback with a specific option parameter, the attacker can trigger the unserialization of this metadata without provider signatures, source-address, transaction-identity, or ownership checks. A POP (Property Oriented Programming) chain—a technique used to execute code by leveraging existing classes in the application—is present in the bundled TCPDF library. This allows attackers to delete arbitrary files on the server, such as wp-config.php, potentially leading to remote code execution if the WordPress installer is re-run against a database controlled by the attacker. Successful exploitation requires an administrator to print an invoice to trigger the file deletion.
Recommendations Update the Welcart e-Commerce plugin for WordPress to version 2.12.2 or later.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19887

Affected Products

Tcpdf
Welcart E-Commerce