🔐 CVE Alert

CVE-2026-87786

HIGH 8.8

Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.

Vendor unknown
Product dewa kirim
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for unknown dewa kirim

Be the first to know when new high vulnerabilities affecting unknown dewa kirim are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Dewa Kirim
0 ≤ 1.0.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/bb94cded-6ec1-488e-8682-555d276d2979/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan