Impact
This flaw is an improper neutralization of input during web page generation that allows Stored XSS in the Welcart e‑Commerce plugin. An attacker can inject malicious script code that will be persisted and later rendered to users, potentially leading to defacement, session hijacking, or the execution of additional malicious payloads in the victim’s browser.
Affected Systems
Welcart e‑Commerce plugin for WordPress, versions 2.11.20 and earlier, are affected; no later versions are known to contain this vulnerability.
Risk and Exploitability
With a CVSS score of 5.9 the vulnerability presents moderate severity, but the EPSS score of <1% indicates a low current exploitation likelihood and the issue is not listed in the CISA KEV catalog. The likely attack vector is a website administrator or malicious entity submitting a value that the plugin accepts without proper sanitization, stores it, and later renders it in a user-facing page where the script will execute.
OpenCVE Enrichment
EUVD