PT-2025-43020 · WordPress · Wordpress+1

Miguel Santareno

·

Publicado

2025-10-22

·

Atualizado

2025-10-22

·

CVE-2025-10651

CVSS v3.1

5.5

Média

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Welcart e-Commerce plugin for WordPress versions through 2.11.22
Description The Welcart e-Commerce plugin for WordPress is susceptible to Stored Cross-Site Scripting through the order mail setting. Insufficient sanitization of the order mail field and a lack of output escaping allow authenticated attackers with Editor-level permissions or higher to inject arbitrary web scripts via the General Setting page. These scripts will execute when an administrator accesses the E-mail Setting page.
Recommendations Update the Welcart e-Commerce plugin to a version later than 2.11.22.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-10651

Produtos afetados

Welcart E-Commerce
Wordpress