Unrated severityNVD Advisory· Published Aug 21, 2026
CVE-2025-15671
CVE-2025-15671
Description
The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.12.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.