Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 21 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Welcart
Welcart welcart E-commerce Wordpress Wordpress wordpress |
|
| Weaknesses | CWE-287 | |
| Vendors & Products |
Welcart
Welcart welcart E-commerce Wordpress Wordpress wordpress |
|
| Metrics |
cvssV3_1
|
Fri, 21 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-613 |
Fri, 21 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request. | |
| Title | Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-21T12:50:13.159Z
Reserved: 2026-07-17T13:44:43.147Z
Link: CVE-2025-15671
Updated: 2026-08-21T12:50:00.469Z
Status : Received
Published: 2026-08-21T07:16:22.960
Modified: 2026-08-21T13:16:27.917
Link: CVE-2025-15671
No data.
OpenCVE Enrichment
Updated: 2026-08-21T12:59:57Z