CVE-2025-62953

8.8

info@welcart · Welcart e-Commerce

A missing authorization vulnerability in the Welcart e-Commerce plugin for WordPress allows authenticated users to perform unauthorized actions due to incorrectly configured access controls.

Executive summary

A missing authorization vulnerability in the Welcart e-Commerce plugin allows authenticated users to bypass access controls, posing a significant risk to site integrity.

Vulnerability

This vulnerability is a Missing Authorization flaw (CWE-862) occurring within the usc-e-shop component. It allows an authenticated user with low privileges to perform actions that should be restricted to higher-privileged accounts.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting a high risk despite the requirement for authenticated access. Successful exploitation could lead to unauthorized modification of e-commerce data, potentially resulting in financial discrepancies, loss of customer trust, and operational disruption.

Remediation

Immediate Action: Update the Welcart e-Commerce plugin to the latest version available beyond 2.11.24 to resolve the access control deficiency.

Proactive Monitoring: Review WordPress administrative access logs for unusual activity or unauthorized configuration changes performed by lower-privileged user accounts.

Compensating Controls: Utilize a Web Application Firewall (WAF) to monitor and block suspicious request patterns directed at the usc-e-shop plugin endpoints.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability represents a critical failure in authorization logic that could be abused by malicious or compromised user accounts. Administrators are strongly advised to verify their current plugin version immediately and apply the necessary security updates to prevent unauthorized access and potential data manipulation within their e-commerce environment.

Sources

Originally found and disclosed by Legion Hunter | Patchstack Bug Bounty Program, per the CVE Program record.