{"api_version":"1","generated_at":"2026-08-12T11:40:52+00:00","cve":"CVE-2026-16066","urls":{"html":"https://cve.report/CVE-2026-16066","api":"https://cve.report/api/cve/CVE-2026-16066.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16066","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16066"},"summary":{"title":"Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name","description":"The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any visitor viewing the product page.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-12 06:18:15","updated_at":"2026-08-12 06:18:15"},"problem_types":["CWE-79 Cross-Site Scripting (XSS)"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/ed3b39a6-493c-490e-af41-c4d04992e19e/","name":"https://wpscan.com/vulnerability/ed3b39a6-493c-490e-af41-c4d04992e19e/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16066","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16066","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Welcart e-Commerce","version":"affected 2.11.34 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Yaswanth Reddy Sunkara","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Welcart e-Commerce","vendor":"Unknown","versions":[{"lessThan":"2.11.34","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Yaswanth Reddy Sunkara"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any visitor viewing the product page."}],"problemTypes":[{"descriptions":[{"description":"CWE-79 Cross-Site Scripting (XSS)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-12T06:00:14.817Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/ed3b39a6-493c-490e-af41-c4d04992e19e/"}],"source":{"discovery":"EXTERNAL"},"title":"Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-16066","datePublished":"2026-08-12T06:00:14.817Z","dateReserved":"2026-07-17T13:08:50.924Z","dateUpdated":"2026-08-12T06:00:14.817Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-12 06:18:15","lastModifiedDate":"2026-08-12 06:18:15","problem_types":["CWE-79 Cross-Site Scripting (XSS)"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16066","Ordinal":"1","Title":"Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Na","CVE":"CVE-2026-16066","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16066","Ordinal":"1","NoteData":"The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any visitor viewing the product page.","Type":"Description","Title":"Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Na"}]}}}