CVE-2026-19914 | Welcart e-Commerce Plugin up to 2.12.1 on WordPress Admin Panel custom_order cross site scripting

SecurityVulns

A vulnerability was found in Welcart e-Commerce Plugin up to 2.12.1 on WordPress. It has been declared as problematic. This affects an unknown part of the component Admin Panel. Executing a manipulation of the argument custom_order can lead to cross site scripting.

The identification of this vulnerability is CVE-2026-19914. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More