WordPress Plugin Vulnerabilities

Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates

Description

The plugin does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Pablo González Pérez, Francisco José Ramírez Vicente, and Iñigo Sánchez Enciso
Submitter
Pablo González Pérez, Francisco José Ramírez Vicente, and Iñigo Sánchez Enciso
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-15 (about 2 days ago)
Added
2026-09-15 (about 1 day ago)
Last Updated
2026-09-15 (about 1 day ago)

Other