Stored Cross-Site Scripting in Welcart e-Commerce Plugin for WordPress
CVE-2026-19914
7.2HIGH
What is CVE-2026-19914?
The Welcart e-Commerce plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the 'custom_order' parameter. This allows unauthenticated attackers to inject malicious web scripts through the guest checkout form. These scripts execute when an administrator accesses the order within the WordPress admin panel, posing a security risk to the site and its users.
Affected Version(s)
Welcart e-Commerce 0 <= 2.12.1