Deserialization Vulnerability in Nanbu Welcart e-Commerce Plugin
CVE-2025-54012
7.2HIGH
What is CVE-2025-54012?
A deserialization of untrusted data vulnerability in the Nanbu Welcart e-Commerce plugin allows for object injection. This security issue affects versions from n/a up to 2.11.16, potentially allowing attackers to exploit the application by manipulating serialized objects. Users of the affected versions should seek to update or secure their installations to mitigate any risks associated with this vulnerability.
Affected Version(s)
Welcart e-Commerce <= 2.11.16