WordPress Plugin Vulnerabilities

Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter

Description

The plugin does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.

Proof of Concept

Affects Plugins

Fixed in 2.12.1

References

Classification

Miscellaneous

Original Researcher
bRpsd
Submitter
bRpsd
Verified
Yes

Timeline

Publicly Published
2026-08-19 (about 2 days ago)
Added
2026-08-19 (about 1 day ago)
Last Updated
2026-08-19 (about 1 day ago)

Other