CVE-2025-62953: WordPress Welcart e-Commerce plugin <= 2.11.24 - Broken Access Control vulnerability
Missing Authorization vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Welcart e-Commerce: from n/a through <= 2.11.24.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62953?
CVE-2025-62953 is classified as a missing authorization vulnerability affecting Welcart e-Commerce version 2.11.24 and below.
How do I fix CVE-2025-62953?
To fix CVE-2025-62953, update Welcart e-Commerce to the latest version that addresses the access control issue.
What are the consequences of CVE-2025-62953?
Exploiting CVE-2025-62953 may allow unauthorized users to gain access to restricted features or data within the e-commerce site.
Which versions of Welcart e-Commerce are affected by CVE-2025-62953?
CVE-2025-62953 affects Welcart e-Commerce from version n/a up to and including version 2.11.24.
Is there a workaround for CVE-2025-62953?
There are currently no known workarounds for CVE-2025-62953 other than upgrading to a secure version.