Unauthenticated Order Settlement in Welcart e-Commerce WordPress Plugin
CVE-2026-15213
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 12 August 2026
Badges
What is CVE-2026-15213?
The Welcart e-Commerce plugin for WordPress is susceptible to a significant vulnerability where it fails to properly verify the authenticity of callback requests related to convenience-store and bank-transfer settlements. This flaw allows an unauthenticated attacker to change the status of an order from unpaid to settled by simply providing the order number and a status flag. Consequently, an unauthorized individual could mark their order as fulfilled without the requirement for signature verification, payment confirmation, or origin checks. This issue, particularly concerning pay-later methods, poses a serious risk of order fulfillment without actual payment, potentially leading to financial losses for merchants.
Affected Version(s)
Welcart e-Commerce 0 < 2.11.33
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved