Product
J2Commerce versions 4.1.5 and earlier are vulnerable to stored XSS via guest checkout, allowing unauthenticated attackers to execute malicious JavaScript in the administrator's browser upon order review.