Description
The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Immediate Patch
AI Analysis

Impact

The Dewa Kirim WordPress plugin version 1.0.0 contains a stored cross‑site scripting flaw that allows unsanitised delivery coordinates entered during checkout to be injected into an inline script. An unauthenticated user can persist malicious JavaScript that will execute in the context of any administrator who later opens the order, exposing sensitive data and enabling session hijacking. The vulnerability is a classic injection flaw (CWE‑79) and can be used to execute arbitrary code in the admin’s browser.

Affected Systems

The flaw affects the Dewa Kirim WordPress plugin provided by the Unknown vendor, for all installations using version 1.0.0 or earlier. WordPress sites running a vulnerable version are at risk until the plugin is updated to a fixed version.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity, while the EPSS score of less than 1% suggests low current exploitation likelihood. It is not listed in the CISA KEV catalog, but the attack vector is inferred to arise from the public checkout interface, allowing an unauthenticated user to submit malicious coordinates that later execute in an administrator’s session.

Generated by OpenCVE AI on September 18, 2026 at 01:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Dewa Kirim plugin to the latest version that eliminates the unsanitised output.
  • If no update is available, remove or sanitize the coordinates field on the checkout page so that any embedded scripts are escaped before storage.
  • As a temporary measure, restrict checkout coordinates input to authenticated users only or disable the feature until a patch is published.

Generated by OpenCVE AI on September 18, 2026 at 01:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.
Title Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:28:45.287Z

Reserved: 2026-09-09T09:23:17.417Z

Link: CVE-2026-87786

cve-icon Vulnrichment

Updated: 2026-09-17T12:11:53.396Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:51.773

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-87786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')