<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:welcart:welcart_e-Commerce:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awelcartwelcart_e-commercewordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 11:05:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awelcartwelcart_e-commercewordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in Welcart e-Commerce Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-welcart-xss/</link><pubDate>Tue, 01 Sep 2026 11:05:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-welcart-xss/</guid><description>An unauthenticated stored XSS vulnerability in the Welcart e-Commerce WordPress plugin (CVE-2026-19914) allows attackers to inject malicious scripts that execute in the context of administrative sessions.</description><content:encoded><![CDATA[<p>The Welcart e-Commerce plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-19914. The flaw exists in the 'custom_order' parameter, which fails to properly sanitize input or escape output during the guest checkout process. Versions up to and including 2.12.1 are affected. An unauthenticated attacker can supply a crafted script within the checkout form fields. When a site administrator navigates to the WordPress dashboard to review the processed order, the malicious script executes in their browser session. This can be leveraged to perform unauthorized administrative actions, steal session tokens, or redirect users to malicious domains, posing a significant risk to the integrity of the WordPress environment.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a high risk to WordPress installations using the Welcart plugin, specifically impacting administrative accounts. Successful exploitation allows for the execution of arbitrary scripts, potentially leading to full site compromise if an administrator session is hijacked. Given the nature of e-commerce plugins, this could result in unauthorized order modifications or the theft of sensitive administrative or customer data.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and IT teams:</p>
<ul>
<li>Update the Welcart e-Commerce plugin to the latest version beyond 2.12.1 immediately to patch CVE-2026-19914.</li>
<li>Implement a Web Application Firewall (WAF) to inspect POST requests to the guest checkout endpoint for common XSS patterns, specifically targeting the 'custom_order' parameter.</li>
<li>Audit administrative access logs for unusual activity originating from the plugin's order management pages.</li>
<li>Review the WordPress admin panel for any injected malicious scripts in order descriptions or custom order fields.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>xss</category><category>wordpress</category><category>cve-2026-19914</category></item></channel></rss>