Impact
The Dewa Kirim WordPress plugin version 1.0.0 contains a stored cross‑site scripting flaw that allows unsanitised delivery coordinates entered during checkout to be injected into an inline script. An unauthenticated user can persist malicious JavaScript that will execute in the context of any administrator who later opens the order, exposing sensitive data and enabling session hijacking. The vulnerability is a classic injection flaw (CWE‑79) and can be used to execute arbitrary code in the admin’s browser.
Affected Systems
The flaw affects the Dewa Kirim WordPress plugin provided by the Unknown vendor, for all installations using version 1.0.0 or earlier. WordPress sites running a vulnerable version are at risk until the plugin is updated to a fixed version.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity, while the EPSS score of less than 1% suggests low current exploitation likelihood. It is not listed in the CISA KEV catalog, but the attack vector is inferred to arise from the public checkout interface, allowing an unauthenticated user to submit malicious coordinates that later execute in an administrator’s session.
OpenCVE Enrichment