{
 "id": "WPSEC-2026-0647",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0647/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0647/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0647/index.md",
 "title": "WPML Multilingual & Multicurrency for WooCommerce <= 5.5.8 - Unauthenticated Session Fixation via Cross-Domain Session Handoff",
 "description": "The WPML Multilingual & Multicurrency for WooCommerce plugin for WordPress is vulnerable to Session Fixation in all versions up to, and including, 5.5.8. This is due to the cross-domain session handoff, which carries a shopper's WooCommerce session to another language domain, accepting a stored handoff entry from any client that presents its identifier, with no expiry and no binding to the client that created it. This makes it possible for unauthenticated attackers to bind a guest shopper's WooCommerce session to a session the attacker controls, by tricking the shopper into following a crafted link. The attacker can then view or alter the cart and customer details held in that session. It does not give access to WordPress accounts. Only sites that serve languages on separate domains with WPML's cross-domain data passing enabled are affected.",
 "plugin": {
  "slug": "woocommerce-multilingual",
  "name": "WPML Multilingual & Multicurrency for WooCommerce",
  "full_name": "WPML Multilingual & Multicurrency for WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/woocommerce-multilingual/",
  "advisories_url": "https://wpsec.com/vuln/plugin/woocommerce-multilingual/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/woocommerce-multilingual"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-384"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.2,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "5.6.3",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 5.6.3"
  ]
 },
 "introduced_in": null,
 "fixed_in": "5.6.3",
 "remediation": "Update to 5.6.3 or later.",
 "fix_released": "2026-10-07T11:47:57+00:00",
 "published": "2026-10-08T12:49:15+00:00",
 "updated": "2026-10-07T14:56:07.720778+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0647/",
  "https://plugins.svn.wordpress.org/woocommerce-multilingual/tags/5.6.3/",
  "https://wordpress.org/plugins/woocommerce-multilingual/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/woocommerce-multilingual",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "High",
  "affected_versions": "High",
  "as_of": "2026-10-08"
 }
}