CVE-2025-15671: Unknown Welcart E-Commerce

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.

Affected products

  • Unknown Welcart E-Commerce: before 2.12.1 (fixed in 2.12.1)

Published 2026-08-21. Last modified 2026-09-29.