WPML Multilingual & Multicurrency for WooCommerce <= 5.5.8 - Unauthenticated Session Fixation via Cross-Domain Session Handoff

Medium 4.2 CWE-384Fixed in 5.6.3
ID
WPSEC-2026-0647
Plugin
WPML Multilingual & Multicurrency for WooCommerce (woocommerce-multilingual)
Affected
all versions before 5.6.3
Remediation
Update to 5.6.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Weakness
CWE-384
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-08
Attack surface
WPML Multilingual & Multicurrency for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The WPML Multilingual & Multicurrency for WooCommerce plugin for WordPress is vulnerable to Session Fixation in all versions up to, and including, 5.5.8. This is due to the cross-domain session handoff, which carries a shopper's WooCommerce session to another language domain, accepting a stored handoff entry from any client that presents its identifier, with no expiry and no binding to the client that created it. This makes it possible for unauthenticated attackers to bind a guest shopper's WooCommerce session to a session the attacker controls, by tricking the shopper into following a crafted link. The attacker can then view or alter the cart and customer details held in that session. It does not give access to WordPress accounts. Only sites that serve languages on separate domains with WPML's cross-domain data passing enabled are affected.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0