Stored Cross-Site Scripting in Welcart e-Commerce Plugin
An unauthenticated stored Cross-Site Scripting vulnerability in the Welcart e-Commerce WordPress plugin allows attackers to inject malicious scripts via settlement notification parameters.
CVE search metadata
CVE search record: CVE-2026-87091. Severity: high. CVSS: 7.2. KEV: no. Product: Welcart e-Commerce (<= 2.12.2). Brief: Stored Cross-Site Scripting in Welcart e-Commerce Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-welcart-xss/
The Welcart e-Commerce plugin for WordPress, in versions up to and including 2.12.2, is vulnerable to a Stored Cross-Site Scripting (XSS) attack. The vulnerability originates in the plugin's Instant Payment Notification (IPN) endpoint, which fails to adequately sanitize the 'rel' and 'option' parameters. Crucially, this endpoint lacks authentication, nonce validation, and signature verification, permitting unauthenticated attackers to submit crafted payloads directly to the application. These payloads are stored within the database and are subsequently executed within the browser context of an administrator when they access the settlement error log view within the WordPress dashboard. This vulnerability poses a significant risk to administrative account security, as successful exploitation could lead to session hijacking or the unauthorized execution of actions within the WordPress environment.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's session. This can lead to full account compromise, unauthorized configuration changes, or the exfiltration of sensitive site data. The target sector includes any organization utilizing the affected Welcart e-Commerce plugin version for WordPress operations.
Recommendation
Update the Welcart e-Commerce plugin to the latest version, which includes patches for input sanitization and verification of IPN parameters. Until patching is completed, implement strict access controls on the IPN endpoint or monitor web server access logs for anomalous POST requests directed at the settlement notification paths.
Detection
Detect attempts to exploit CVE-2026-87091 by monitoring for HTTP POST requests to the plugin's IPN endpoint that contain script tags or suspicious JavaScript patterns within the 'rel' or 'option' parameters.
Immediate actions
Update Welcart e-Commerce plugin to the latest version immediately
Mitigations
Upgrade Welcart e-Commerce to a patched release
CVE-2026-87091
Detection coverage 1
Detects CVE-2026-87091 Exploitation - Stored XSS in Welcart IPN
highDetects unauthenticated HTTP POST requests targeting the Welcart IPN endpoint with script-related payloads in the rel or option parameters.
Detection queries are available on the platform. Get full rules →