Impact
The Welcart e‑Commerce plugin for WordPress is vulnerable to a stored Cross‑Site Scripting flaw triggered via the 'custom_order' parameter. The weakness, identified as CWE‑79, arises from insufficient input sanitization and output escaping. Unauthenticated attackers can submit arbitrary JavaScript in the guest checkout form, which is then saved into an order record and executed whenever an administrator views that order in the WordPress admin panel.
Affected Systems
Welcart e‑Commerce by uscnanbu is affected on all versions up to and including 2.12.1. Administrators using these releases are exposed to the vulnerability.
Risk and Exploitability
The CVSS score of 7.2 indicates a high risk severity. Because no authentication is required to inject the payload, the attack can be initiated remotely from any site that hosts the plugin. The vulnerability is not listed in the CISA KEV catalog; however, the simplicity of exploitation—entering a custom order on a public checkout page—suggests a realistic exploitation probability. Attackers could run scripts with the permissions of the admin user, enabling credential theft, defacement, or further privilege escalation.
OpenCVE Enrichment