CVE-2026-19887 | Welcart e-Commerce Plugin up to 2.12.1 on WordPress Telecom EDY Payment Callback usces_action_acting_transaction option deserialization
A vulnerability categorized as critical has been discovered in Welcart e-Commerce Plugin up to 2.12.1 on WordPress. Affected by this issue is the function usces_action_acting_transaction of the component Telecom EDY Payment Callback. The manipulation of the argument option results in deserialization.
This vulnerability is identified as CVE-2026-19887. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More