CVE-2025-15671 PUBLISHED

Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter

Assigner: WPScan
Reserved: 17.07.2026 Published: 21.08.2026 Updated: 21.08.2026

The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.

Product Status

Vendor Unknown
Product Welcart e-Commerce
Versions Default: unaffected
  • affected from 0 to 2.12.1 (excl.)

Credits

  • bRpsd finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE