Stored Cross-Site Scripting Vulnerability in Welcart e-Commerce Plugin for WordPress
CVE-2026-87091

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2026

What is CVE-2026-87091?

The Welcart e-Commerce plugin for WordPress is susceptible to Stored Cross-Site Scripting because it inadequately sanitizes and escapes user input, particularly through Settlement Notification Parameters. This vulnerability allows unauthenticated attackers to inject malicious web scripts that execute when users access affected pages. A lack of authentication, nonce validation, or signature verification enables these attackers to submit harmful payloads directly to the IPN endpoint, which are subsequently stored and rendered in the admin's settlement error log view, posing serious security risks to the site.

Affected Version(s)

Welcart e-Commerce 0 <= 2.12.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

minhgalaxy
.