CVE-2025-15671

Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter

The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.


We have discovered 6,367 live websites that are affected by CVE-2025-15671.

Run a Free Instant Scan




Affected Software

Product  Welcart
Category Ecommerce
Vulnerable Domains6,367 live websites (100% of Welcart install base)
Vulnerable Versions
  • from 0 through 2.12.1
Vulnerable Versions Count192 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Aug 21, 2026
  • Updated - Aug 21, 2026

Credits

  • bRpsd (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-15671
United States135 websites



Japan5,898 websites
GB6 websites
China5 websites
Canada3 websites
Spain3 websites
Australia2 websites
Germany2 websites
Italy2 websites

Website Distribution by TLD

Number of websites using CVE-2025-15671
.com3,251 websites
.jp1,355 websites
.co.jp827 websites
.net465 websites
.info73 websites
.org68 websites
.co5 websites
.it3 websites
.be2 websites
.com.au2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-15671

Top websites that are affected by CVE-2025-15671. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.jp Japan**,***
*******.com United States**,***
*********.com ***,***
********.net Japan***,***
************.com ***,***
*****.**.jp Japan***,***
*****************.com Japan***,***
*********.jp Japan***,***
************.**.jp Japan***,***
******.**.jp Japan***,***
See full domain list

FAQ

CVE-2025-15671 is Improper Authentication in Welcart
A total of 6,367 websites have been identified as vulnerable to CVE-2025-15671, based on global website indexing conducted by WebTechSurvey.
The Welcart is affected by the CVE-2025-15671 vulnerability.
Welcart versions up to 2.12.1 are vulnerable to CVE-2025-15671.
CVE-2025-15671 is resolved in version 2.12.1 of Welcart.