HIGH
CVE-2026-87786
CVSS
8.8
Description
The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.28%
Probability of exploitation in next 30 days
20.3th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.