SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2025-15671

MEDIUM · CVSS 5.4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Welcart e-Commerce plugin for WordPress prior to version 2.12.1 is vulnerable due to improper session management, allowing attackers to exploit session fixation by using a user-supplied request parameter. This can lead to unauthorized account takeover of shop members after they log in. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of account compromise.

CVE
CVE-2025-15671
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%
WordPress

Original NVD Description

The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.