Loading market data...
← Back to CVE feed

CVE-2026-87786

HIGH CVSS 8.8 View on NVD ↗

Description

The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published: Sep 17, 2026 06:16 UTC Modified: Sep 17, 2026 13:16 UTC