Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 3 min 134 bronnen 1 kritiek 2 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2025-11888

LOW · 2.7 CVSS Gepubliceerd: CWE-863

Beschrijving NL

De ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution-plug-in voor WordPress is kwetsbaar voor ongeoorloofde wijziging van gegevens vanwege een onvoldoende capaciteitscontrole van de post_deactive() -functie en post_activate() -functie in alle versies tot en met 4.8.4. Dit maakt het mogelijk voor geverifieerde aanvallers, met toegang op Editor-niveau en hoger, om licenties te activeren en te deactiveren.

Origineel (Engels) tonen

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it possible for authenticated attackers, with Editor-level access and above, to activate and deactivate licenses.

References