# WPML Multilingual & Multicurrency for WooCommerce <= 5.5.8 - Unauthenticated Session Fixation via Cross-Domain Session Handoff

- **ID:** WPSEC-2026-0647
- **Plugin:** WPML Multilingual & Multicurrency for WooCommerce (`woocommerce-multilingual`), https://wordpress.org/plugins/woocommerce-multilingual/
- **Affected versions:** all versions before 5.6.3
- **Fixed in:** 5.6.3 (Update to 5.6.3 or later.)
- **Severity:** Medium 4.2 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N)
- **Weakness:** CWE-384
- **Usage among sites WPSec scans:** plugin High, affected versions High (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woocommerce-multilingual
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0647/

## Description

The WPML Multilingual & Multicurrency for WooCommerce plugin for WordPress is vulnerable to Session Fixation in all versions up to, and including, 5.5.8. This is due to the cross-domain session handoff, which carries a shopper's WooCommerce session to another language domain, accepting a stored handoff entry from any client that presents its identifier, with no expiry and no binding to the client that created it. This makes it possible for unauthenticated attackers to bind a guest shopper's WooCommerce session to a session the attacker controls, by tricking the shopper into following a crafted link. The attacker can then view or alter the cart and customer details held in that session. It does not give access to WordPress accounts. Only sites that serve languages on separate domains with WPML's cross-domain data passing enabled are affected.

## References

- https://wpsec.com/vuln/WPSEC-2026-0647/
- https://plugins.svn.wordpress.org/woocommerce-multilingual/tags/5.6.3/
- https://wordpress.org/plugins/woocommerce-multilingual/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0647/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
