Impact
This vulnerability arises from the Welcart e‑Commerce WordPress plugin not sanitising or escaping the product name field before rendering it on product pages. Users with the Author role or higher can inject arbitrary JavaScript that will execute in the browsers of any visitor who views the affected product. Such a stored XSS flaw can lead to cookie theft, session hijacking, defacement, or arbitrary client‑side code execution, compromising the confidentiality and integrity of user accounts and potentially enabling further attacks against the host site.
Affected Systems
The flaw affects all installations of the Welcart e‑Commerce plugin running any version older than 2.11.34. The vulnerability is present in any WordPress site that uses this plugin version, regardless of other configurations.
Risk and Exploitability
The exploit requires that an attacker have Author‑level or higher privileges to edit a product name, after which the malicious script is stored and then served to all visitors. Because the input is rendered without neutralisation, the attack is trivial once the prerequisite role is achieved. No network‑side conditions are documented, so exploitation depends mainly on access control. While the CVSS score is not provided, the lack of mitigation and the ease of exploitation place the risk in the high to critical range. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, indicating no confirmed widespread exploitation yet.
OpenCVE Enrichment