Impact
Welcart e‑Commerce is vulnerable to a stored cross‑site scripting flaw that arises when the Payment Processing endpoint accepts unfiltered "rel" and "option" parameters. Unauthenticated actors can submit malicious JavaScript that is saved and later rendered in the administrator's settlement error log view, enabling arbitrary code execution in the context of a logged‑in admin. This can lead to theft of session cookies, credential compromise, data tampering, or page defacement.
Affected Systems
All installations of the Welcart e‑Commerce WordPress plugin up to and including version 2.12.2 are affected. Earlier releases from the same vendor share the same vulnerable code path and are therefore also impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2 and is not listed in the CISA KEV catalog, with no EPSS score available. Attackers can exploit it remotely by sending simple HTTP requests to the IPN endpoint without any authentication; no special privileges or infrastructure are required. The consequence is significant since it grants full control over the admin interface once triggered.
OpenCVE Enrichment