The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.
We have discovered 6,367 live websites that are affected by CVE-2025-15671.
| 135 websites | |
| 5,898 websites | |
| 6 websites | |
| 5 websites | |
| 3 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites |
| .com | 3,251 websites |
| .jp | 1,355 websites |
| .co.jp | 827 websites |
| .net | 465 websites |
| .info | 73 websites |
| .org | 68 websites |
| .co | 5 websites |
| .it | 3 websites |
| .be | 2 websites |
| .com.au | 2 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.jp | **,*** | ||
| *******.com | **,*** | ||
| *********.com | ***,*** | ||
| ********.net | ***,*** | ||
| ************.com | ***,*** | ||
| *****.**.jp | ***,*** | ||
| *****************.com | ***,*** | ||
| *********.jp | ***,*** | ||
| ************.**.jp | ***,*** | ||
| ******.**.jp | ***,*** |
FAQ