Stored Cross-Site Scripting Vulnerability in Welcart e-Commerce Plugin for WordPress
CVE-2025-0511
6.1MEDIUM
What is CVE-2025-0511?
The Welcart e-Commerce plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping. Attackers can exploit this flaw through the 'name' parameter, allowing them to inject arbitrary scripts that execute in users' browsers when they visit affected pages. This issue affects all versions of the plugin up to and including 2.11.9, posing a risk to site integrity and user safety.
Affected Version(s)
Welcart e-Commerce * <= 2.11.9