CVE-2025-58984: WordPress Welcart e-Commerce Plugin <= 2.11.20 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through <= 2.11.20.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nanbu Welcart e-Commerce allows Stored XSS. This issue affects Welcart e-Commerce: from n/a through 2.11.20.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58984?
CVE-2025-58984 has a severe impact due to its potential for Stored XSS attacks.
How do I fix CVE-2025-58984?
To fix CVE-2025-58984, update the Welcart e-Commerce plugin to version 2.11.21 or later.
What kind of vulnerability is CVE-2025-58984?
CVE-2025-58984 is classified as a Cross-site Scripting (XSS) vulnerability.
Which versions are affected by CVE-2025-58984?
CVE-2025-58984 affects Welcart e-Commerce versions up to and including 2.11.20.
Who should be concerned about CVE-2025-58984?
Website owners using affected versions of the Welcart e-Commerce plugin should be concerned about CVE-2025-58984.