The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitize a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above to perform SQL injection attacks. This vulnerability has a medium severity with a CVSS score of 6.5. The CVE record was published on 2026-08-06T07:16:28.197Z and has not been modified since then. Affected [truncated]