PT-2025-46782 · WordPress · Welcart E-Commerce

Marcin Dudek

·

Published

2025-11-13

·

Updated

2025-11-13

·

CVE-2025-12979

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Welcart e-Commerce plugin for WordPress versions prior to 2.11.25
Description The Welcart e-Commerce plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check on the usces export action. An unauthenticated attacker can access configured payment credentials (such as PayPal API secrets), business contact details, mail templates, and other operational settings tied to the store.
Recommendations Update to version 2.11.25 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12979

Affected Products

Welcart E-Commerce