Understanding and Defending Against CVE-2026-19887: PHP Object Injection in Welcart e-Commerce Plugin
CVE-2026-19887 is a PHP Object Injection vulnerability in the Welcart e-Commerce plugin for WordPress, allowing unauthenticated attackers to delete arbitrary files and potentially achieve remote code execution. This vulnerability has a CVSS score of 8.8 and is considered high severity. The vulnerability is caused by the deserialization of untrusted input in the Telecom EDY payment callback.