Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.4epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any visitor viewing the product page.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · Welcart e-Commercepublic PoCs found — 1
cve_referencewpscan.com/vulnerability/ed3b39a6-493c-490e-af41-c4d04992e19e/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.