
CVE-2026-16066 The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the … https://www.cve.org/CVERecord?id=CVE-2026-16066
Post summary
The CVE discloses an unsanitized product field in Welcart e‑Commerce WordPress plugin, mitigated in version 2.11.34.

