CVE-2025-9367

Published
View on NVD ↗
CVSS v3
5.5
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

<p>Welcart is a free WordPress e-commerce plugin with the top market share in Japan. It offers extensive features and flexibility to help you build your own online store with ease. Compatible with PHP 7.4 to 8.3.</p> <h4>SHOPPING CART SYSTEM</h4> <p>Sell physical products with no limits on the number of items or categories. Manage inventory with SKU codes and configure flexible pricing and shipping options. Additional extension plugins are available to support digital content sales and subscriptions. Over 16 payment services can be added through the official Welcart website.</p> <p><a href="https://www.welcart.com/wc-settlement/" rel="nofollow ugc">Welcart Payment services (Japanese)</a></p> <h4>DESIGN</h4> <p>A free responsive theme (Welcart Basic) is available, along with premium themes. You can customize the design and layout however you like.</p> <p><a href="https://www.welcart.com/archives/category/item/itemgenre/template/" rel="nofollow ugc">Welcart Theme downloads (Japanese)</a></p> <h4>MANAGING SYSTEM</h4> <p>Order data is automatically saved and updated in the database. The order list page offers powerful filtering by customer information, date, product type, and more. From the order editing page, you can modify order details, send confirmation emails, download receipt PDFs, and more.</p> <h4>MEMBERSHIP SYSTEM</h4> <p>Welcart includes a built-in membership system with no additional plugins required. The member list page supports searching by customer information and purchase history. A point system is also available for members.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
1.29M