CVE-2025-61922
critical · 9.1PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
9.1
CVSS
0.5%
EPSS (exploit prob.)
42nd
EPSS percentile
2025-10-16
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| prestashop | prestashop_checkout | >= 1.3.0, < 7.4.4.1 |
| prestashop | prestashop_checkout | >= 7.5.0.1, < 7.5.0.5 |
| prestashop | prestashop_checkout | >= 8.3.1.0, < 8.4.4.1 |
| prestashop | prestashop_checkout | >= 8.5.0.0, < 8.5.0.5 |
| prestashop | prestashop_checkout | >= 9.4.3.1, < 9.5.0.5 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-61922