HIGH
hands01
CVE published 2026-01-08
CVE-2025-68890
A Cross-site Scripting vulnerability in the e-shops-cart2 plugin for WordPress allows DOM-Based XSS. This issue affects e-shops from n/a through <= 1.0.4. The vulnerability could allow attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data theft. Defenders should assess exposure and apply necessary patches or mitigations. The CVE record and NVD entry prov [truncated]