Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw in the Welcart e‑Commerce WordPress plugin. It allows an attacker to inject arbitrary script into the plugin’s output, which is then executed in the browser of any visitor to the affected site. Potential user‑facing consequences include session hijack, credential theft, defacement or redirect to malicious sites (inferred). The weakness is a classic input validation issue and is identified as CWE‑79.
Affected Systems
Any WordPress site running the Welcart e‑Commerce plugin version 2.11.31 or older is affected. Sites that have not upgraded past 2.11.31 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. EPSS score is not available; however the lack of authentication requirement and widespread use of the plugin make exploitation likely. The vulnerability is not currently listed in the CISA KEV catalog. An attacker can exploit the flaw by sending a specially crafted request to a vulnerable endpoint, injecting malicious JavaScript that is rendered in the browser of any visitor (inferred).
OpenCVE Enrichment