CVE-2025-11888
Beschrijving NL
De ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution-plug-in voor WordPress is kwetsbaar voor ongeoorloofde wijziging van gegevens vanwege een onvoldoende capaciteitscontrole van de post_deactive() -functie en post_activate() -functie in alle versies tot en met 4.8.4. Dit maakt het mogelijk voor geverifieerde aanvallers, met toegang op Editor-niveau en hoger, om licenties te activeren en te deactiveren.
Origineel (Engels) tonen
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it possible for authenticated attackers, with Editor-level access and above, to activate and deactivate licenses.