CVE 9.1 CRITICAL

PrestaShop Checkout allows customer account takeover via email_CVE-2025-61922

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

Basic Information

ID CVE-2025-61922
Source GitHub_M
Published Oct 16, 2025 at 17:26

Affected Product

Vendor PrestaShopCorp
Product ps_checkout
Version < 4.4.1
Affected Versions PrestaShopCorp ps_checkout < 4.4.1
PrestaShopCorp ps_checkout >= 5.0.0, < 5.0.5

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.