CVE-2025-10651: Welcart e-Commerce <= 2.11.22 - Authenticated (Editor+) Stored Cross-Site Scripting via order_mail
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ordermail' setting in versions up to, and including, 2.11.22. This is due to insufficient sanitization on the ordermail field and a lack of escaping on output. This makes it possible for authenticated attackers, with Editor-level permissions and above, to inject arbitrary web scripts via the General Setting page that will execute when an administrator accesses the E-mail Setting page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10651?
CVE-2025-10651 has a medium severity rating due to the potential for Stored Cross-Site Scripting.
How do I fix CVE-2025-10651?
To fix CVE-2025-10651, update the Welcart e-Commerce plugin to version 2.11.23 or later.
Which versions of Welcart e-Commerce are affected by CVE-2025-10651?
CVE-2025-10651 affects Welcart e-Commerce versions up to and including 2.11.22.
What type of vulnerability is CVE-2025-10651?
CVE-2025-10651 is a Stored Cross-Site Scripting vulnerability.
What causes CVE-2025-10651?
CVE-2025-10651 is caused by insufficient sanitization and lack of escaping in the 'order_mail' field.