Description
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in versions up to, and including, 2.11.22. This is due to insufficient sanitization on the order_mail field and a lack of escaping on output. This makes it possible for authenticated attackers, with Editor-level permissions and above, to inject arbitrary web scripts via the General Setting page that will execute when an administrator accesses the E-mail Setting page.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
* (semver)
Timeline
| 2025-09-17: | Vendor Notified |
| 2025-10-21: | Disclosed |
Credits
Miguel Santareno
References
www.wordfence.com/...-64ed-4330-9c76-1a8d2e2d307d?source=cve
plugins.trac.wordpress.org/changeset/3374769/usc-e-shop
www.welcart.com/archives/26052.html