PHP Object Injection Vulnerability in Welcart e-Commerce Plugin for WordPress
CVE-2026-19887
What is CVE-2026-19887?
The Welcart e-Commerce plugin for WordPress is affected by a PHP Object Injection vulnerability due to the deserialization of untrusted input in its Telecom EDY payment callback function. Attackers can exploit this flaw by storing malicious 'reserve' key/value pairs as order metadata during public checkouts. By triggering the callback with a crafted 'option' parameter, an attacker can unserialize and execute arbitrary methods. As a consequence, they may delete critical files on the server, including wp-config.php, which opens the door to potential remote code execution if the attacker subsequently reinstalls WordPress with a manipulated database. This vulnerability is particularly concerning as it does not require any additional plugins or themes to exploit.
Affected Version(s)
Welcart e-Commerce 0 <= 2.12.1