SQL Injection Vulnerability in Welcart Plugin for WordPress
CVE-2026-16080
6.5MEDIUM
What is CVE-2026-16080?
The Image Uploader for Welcart plugin for WordPress is susceptible to SQL Injection through the 'post_title' parameter due to improper escaping of user-supplied data. This vulnerability affects all plugin versions up to and including 1.4.6. Authenticated attackers with author-level access can exploit this weakness by injecting additional SQL queries into existing ones, enabling unauthorized access to sensitive database information.
Affected Version(s)
Image Uploader for Welcart 0 <= 1.4.6