PT-2026-86327 · WordPress+1 · Welcart E-Commerce+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Welcart e-Commerce plugin for WordPress versions prior to 2.12.2
Description
PHP Object Injection occurs due to the deserialization of untrusted input within the Telecom EDY payment callback
usces action acting transaction(). Unauthenticated attackers can store arbitrary reserve key/value pairs as order metadata during a public checkout. By invoking the callback with a specific option parameter, the attacker can trigger the unserialization of this metadata without provider signatures, source-address, transaction-identity, or ownership checks. A POP (Property Oriented Programming) chain—a technique used to execute code by leveraging existing classes in the application—is present in the bundled TCPDF library. This allows attackers to delete arbitrary files on the server, such as wp-config.php, potentially leading to remote code execution if the WordPress installer is re-run against a database controlled by the attacker. Successful exploitation requires an administrator to print an invoice to trigger the file deletion.Recommendations
Update the Welcart e-Commerce plugin for WordPress to version 2.12.2 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tcpdf
Welcart E-Commerce