CVE-2025-54012

7.2

nanbu · Welcart e-Commerce

A deserialization of untrusted data vulnerability in the Welcart e-Commerce plugin allows for object injection, potentially leading to unauthorized system impact.

Executive summary

A high-severity object injection vulnerability in the Welcart e-Commerce plugin poses a significant risk of unauthorized code execution to affected WordPress environments.

Vulnerability

This vulnerability is a deserialization of untrusted data flaw (CWE-502) within the usc-e-shop component, which can be triggered by an authenticated administrator to achieve object injection.

Business impact

Successful exploitation of this vulnerability permits an attacker to perform object injection, which often results in remote code execution, unauthorized data modification, or service disruption. Given the CVSS score of 7.2, this vulnerability represents a high risk to the confidentiality, integrity, and availability of the e-commerce platform and its underlying server infrastructure.

Remediation

Immediate Action: Monitor the vendor for the release of a security update and apply the patch immediately upon availability.

Proactive Monitoring: Review administrative access logs for suspicious activity and monitor server process behavior for unauthorized execution patterns or unexpected spikes in resource utilization.

Compensating Controls: Implement a Web Application Firewall with rules configured to detect and block malicious serialized objects in HTTP requests to the target application.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this flaw warrants an immediate review of the affected infrastructure to identify any instances of the vulnerable plugin version. Security teams must prioritize applying the forthcoming patch and maintain heightened vigilance over administrative account usage until the environment is fully remediated.

More nanbu CVEs

Sources

Originally found and disclosed by 63n0 | Patchstack Bug Bounty Program, per the CVE Program record.