
🚨*CVE* CVE-2025-15671 The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplie… https://www.cve.org/CVERecord?id=CVE-2025-15671 ----- Traducción: CVE-2025-15671 El … http://infoflow.cloud`
Post summary
The post announces CVE‑2025‑15671 for the Welcart e‑Commerce WordPress plugin, describing a session‑fixation vulnerability but providing no PoC, exploit code, remediation, or evidence of active exploitation.


