Sceawere
Vulnerability Detail
CVE-2026-96761UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in Welcart e-Commerce
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Welcart
- Product
- Welcart e-Commerce
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Welcart Welcart e-Commerce usc-e-shop allows Reflected XSS.This issue affects Welcart e-Commerce: from n/a through 2.12.3.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:45.840Z",
"pubdate": "2026-10-09T10:16:45.840Z",
"executiveSummary": "The Welcart e-Commerce plugin for WordPress contains an Improper Neutralization of Input During Web Page Generation vulnerability, classified as a Reflected Cross-Site Scripting (XSS) flaw.\nThis vulnerability impacts Welcart e-Commerce versions from n/a through 2.12.3, affecting all deployments running these iterations.\nThe flaw allows unauthenticated attackers to inject malicious scripts into web pages returned to users, leading to unauthorized actions performed in the context of the user's browser session.\nThe risk implication is significant as successful exploitation could lead to session hijacking, credential theft, or unauthorized redirection, potentially compromising administrative or customer accounts.\nExploitation requires the attacker to trick a targeted user into visiting a specially crafted URL containing the malicious payload, which is then reflected by the application back to the victim's browser.",
"technicalDetails": "The vulnerability resides in the input handling logic of the Welcart e-Commerce plugin, specifically where user-supplied parameters are reflected in the HTTP response without adequate sanitization or output encoding.\nThis constitutes a classic Reflected Cross-Site Scripting (XSS) attack vector. The application fails to validate or escape inputs provided via URL parameters or form submissions before embedding them into the HTML document structure of the dynamically generated page.\nIn a typical attack flow, the attacker identifies an endpoint within the Welcart plugin that reflects a query parameter into the HTML output. The attacker then crafts a malicious URL containing a payload—typically a JavaScript snippet encapsulated within script tags or event handlers—and induces a legitimate user, such as an administrator, to navigate to this crafted link.\nUpon the victim's request to the server, the Welcart application processes the malicious parameter and includes the payload directly in the source code of the generated page. When the victim's browser renders the response, it interprets the attacker-supplied script as legitimate content originating from the trusted site. This results in the execution of the payload within the security context of the user's session.\nBecause the payload executes within the target site's origin, it can access sensitive browser-stored data, including session cookies, local storage, and authentication tokens. Furthermore, the attacker can leverage this execution to perform actions on behalf of the user, such as modifying plugin configurations, altering order details, or performing unauthorized administrative actions, provided the victim holds such privileges.\nThe vulnerability does not require prior authentication to the target system; it relies solely on the user's interaction with the malicious link while authenticated. As long as the victim has an active session with the site, the payload inherits that session's permissions. The scope of impact is limited to the user's browser, but the resulting actions may have persistent effects on the site's database or administrative state, depending on the capabilities exposed to the user being targeted."
}