{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/welcart-e-commerce--2.12.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:welcart:e_commerce:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-87091"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Welcart e-Commerce (\u003c= 2.12.2)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["Welcart"],"content_html":"\u003cp\u003eThe Welcart e-Commerce plugin for WordPress, in versions up to and including 2.12.2, is vulnerable to a Stored Cross-Site Scripting (XSS) attack. The vulnerability originates in the plugin's Instant Payment Notification (IPN) endpoint, which fails to adequately sanitize the 'rel' and 'option' parameters. Crucially, this endpoint lacks authentication, nonce validation, and signature verification, permitting unauthenticated attackers to submit crafted payloads directly to the application. These payloads are stored within the database and are subsequently executed within the browser context of an administrator when they access the settlement error log view within the WordPress dashboard. This vulnerability poses a significant risk to administrative account security, as successful exploitation could lead to session hijacking or the unauthorized execution of actions within the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's session. This can lead to full account compromise, unauthorized configuration changes, or the exfiltration of sensitive site data. The target sector includes any organization utilizing the affected Welcart e-Commerce plugin version for WordPress operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Welcart e-Commerce plugin to the latest version, which includes patches for input sanitization and verification of IPN parameters. Until patching is completed, implement strict access controls on the IPN endpoint or monitor web server access logs for anomalous POST requests directed at the settlement notification paths.\u003c/p\u003e\n\u003ch2 id=\"detection\"\u003eDetection\u003c/h2\u003e\n\u003cp\u003eDetect attempts to exploit CVE-2026-87091 by monitoring for HTTP POST requests to the plugin's IPN endpoint that contain script tags or suspicious JavaScript patterns within the 'rel' or 'option' parameters.\u003c/p\u003e\n","date_modified":"2026-10-03T06:54:11Z","date_published":"2026-10-03T06:54:11Z","id":"https://feed.craftedsignal.io/briefs/2026-10-welcart-xss/","summary":"An unauthenticated stored Cross-Site Scripting vulnerability in the Welcart e-Commerce WordPress plugin allows attackers to inject malicious scripts via settlement notification parameters.","title":"Stored Cross-Site Scripting in Welcart e-Commerce Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-welcart-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Welcart E-Commerce (\u003c= 2.12.2)","version":"https://jsonfeed.org/version/1.1"}