CVE-2026-87786
Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.
| Vendor | unknown |
| Product | dewa kirim |
| Published | Sep 17, 2026 |
| Last Updated | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown dewa kirim
Be the first to know when new high vulnerabilities affecting unknown dewa kirim are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Dewa Kirim
0 ≤ 1.0.0
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan