rootpwn

high · CVSS v3 7.2 · EPSS 0.00314

CVE-2026-87091

The Welcart e-Commerce plugin for WordPress is vulnerable to stored XSS via settlement notification parameters. Unauthenticated attackers ca

Overview

The Welcart e-Commerce plugin for WordPress is vulnerable to stored XSS via settlement notification parameters. Unauthenticated attackers can inject scripts that execute when administrators view settlement error logs, potentially compromising session data or defacing the site. This flaw allows attackers to execute arbitrary code in the admin context.

Description

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Settlement Notification Parameters in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The IPN endpoint accepts the 'rel' and 'option' parameters with no authentication, nonce validation, or signature verification, meaning any unauthenticated attacker can directly submit malicious payloads that are stored and later rendered in the administrator's settlement error log view.

Impact

Confidentiality: attackers can steal admin session cookies or other sensitive data. Integrity: malicious scripts can alter the appearance or content of the settlement error log view. Availability: not directly affected. Impacted parties: WordPress site administrators using the vulnerable Welcart plugin.

Remediation

Upgrade to Welcart 2.12.3 or later. If upgrade is not possible, disable or restrict the IPN endpoint to authenticated users only, implement nonce validation, and sanitize all input parameters before storing or rendering. Monitor the admin logs for suspicious entries.

Risk context

The vulnerability has a high CVSS v3 score of 7.2, but the EPSS score of 0.00314 indicates a low likelihood of exploitation. Nonetheless, the high impact on admin credentials warrants prompt patching or mitigation.

Affected products

  • Welcart e-Commerce plugin

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00314

XSS WordPress Welcart StoredXSS Admin IPN HighSeverity

← All CVEs