PT-2025-43020 · WordPress · Wordpress+1

Miguel Santareno

·

Published

2025-10-22

·

Updated

2025-10-22

·

CVE-2025-10651

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Welcart e-Commerce plugin for WordPress versions through 2.11.22
Description The Welcart e-Commerce plugin for WordPress is susceptible to Stored Cross-Site Scripting through the order mail setting. Insufficient sanitization of the order mail field and a lack of output escaping allow authenticated attackers with Editor-level permissions or higher to inject arbitrary web scripts via the General Setting page. These scripts will execute when an administrator accesses the E-mail Setting page.
Recommendations Update the Welcart e-Commerce plugin to a version later than 2.11.22.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10651

Affected Products

Welcart E-Commerce
Wordpress