CVE-2025-54012: WordPress Welcart e-Commerce Plugin <= 2.11.16 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Object Injection.This issue affects Welcart e-Commerce: from n/a through <= 2.11.16.
Other sources
Deserialization of Untrusted Data vulnerability in nanbu Welcart e-Commerce allows Object Injection. This issue affects Welcart e-Commerce: from n/a through 2.11.16.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54012?
CVE-2025-54012 has a high severity rating due to its potential for object injection vulnerabilities.
How do I fix CVE-2025-54012?
To fix CVE-2025-54012, upgrade your Welcart e-Commerce installation to version 2.11.17 or later.
What are the risks associated with CVE-2025-54012?
The risks associated with CVE-2025-54012 include unauthorized access and manipulation of data due to the deserialization of untrusted data.
Which versions of Welcart e-Commerce are affected by CVE-2025-54012?
CVE-2025-54012 affects Welcart e-Commerce versions up to and including 2.11.16.
Does CVE-2025-54012 affect the WordPress Welcart e-Commerce Plugin?
Yes, CVE-2025-54012 also affects the WordPress Welcart e-Commerce Plugin versions up to and including 2.11.16.