Unauthenticated Broken Access Control in Welcart e-Commerce by Welcart
CVE-2026-49775
6.5MEDIUM
What is CVE-2026-49775?
An unauthenticated broken access control vulnerability in the Welcart e-Commerce plugin allows unauthorized users to bypass access restrictions. This can lead to exposure of sensitive information or manipulation of site data by exploiting vulnerabilities in versions 2.11.28 and below. It is crucial for users to apply updates and implement security best practices to mitigate potential risks.
Affected Version(s)
Welcart e-Commerce <= 2.11.28