Skip to content
Threat Feed
high advisory

Stored Cross-Site Scripting in Welcart e-Commerce Plugin

An unauthenticated stored Cross-Site Scripting vulnerability in the Welcart e-Commerce WordPress plugin allows attackers to inject malicious scripts via settlement notification parameters.

CVE search metadata

CVE search record: CVE-2026-87091. Severity: high. CVSS: 7.2. KEV: no. Product: Welcart e-Commerce (<= 2.12.2). Brief: Stored Cross-Site Scripting in Welcart e-Commerce Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-welcart-xss/

The Welcart e-Commerce plugin for WordPress, in versions up to and including 2.12.2, is vulnerable to a Stored Cross-Site Scripting (XSS) attack. The vulnerability originates in the plugin's Instant Payment Notification (IPN) endpoint, which fails to adequately sanitize the 'rel' and 'option' parameters. Crucially, this endpoint lacks authentication, nonce validation, and signature verification, permitting unauthenticated attackers to submit crafted payloads directly to the application. These payloads are stored within the database and are subsequently executed within the browser context of an administrator when they access the settlement error log view within the WordPress dashboard. This vulnerability poses a significant risk to administrative account security, as successful exploitation could lead to session hijacking or the unauthorized execution of actions within the WordPress environment.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's session. This can lead to full account compromise, unauthorized configuration changes, or the exfiltration of sensitive site data. The target sector includes any organization utilizing the affected Welcart e-Commerce plugin version for WordPress operations.

Recommendation

Update the Welcart e-Commerce plugin to the latest version, which includes patches for input sanitization and verification of IPN parameters. Until patching is completed, implement strict access controls on the IPN endpoint or monitor web server access logs for anomalous POST requests directed at the settlement notification paths.

Detection

Detect attempts to exploit CVE-2026-87091 by monitoring for HTTP POST requests to the plugin's IPN endpoint that contain script tags or suspicious JavaScript patterns within the 'rel' or 'option' parameters.


Immediate actions

Update Welcart e-Commerce plugin to the latest version immediately

IT Operations 24h

Mitigations

Upgrade Welcart e-Commerce to a patched release

immediate IT Operations

CVE-2026-87091

Detection coverage 1

Detects CVE-2026-87091 Exploitation - Stored XSS in Welcart IPN

high

Detects unauthenticated HTTP POST requests targeting the Welcart IPN endpoint with script-related payloads in the rel or option parameters.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →