WordPress · Welcart E-Commerce · CVE-2025-15671
**Name of the Vulnerable Software and Affected Versions**
Welcart e-Commerce versions prior to 2.12.1
**Description**
This issue occurs because the software fails to regenerate the session identifier during authentication and accepts a session identifier provided via a user-supplied request parameter. This allows an unauthenticated attacker to perform session fixation, which involves pre-setting a user's session ID, enabling the attacker to take over a customer account once the victim authenticates through a specially crafted request. The vulnerable parameter is `uscesid`.
**Recommendations**
Update to version 2.12.1 or later.