CVE-2025-61922

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:*
cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:*
cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:*
cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:*
cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:*

History

29 Dec 2025, 20:06

Type Values Removed Values Added
First Time Prestashop
Prestashop prestashop Checkout
References () https://github.com/PrestaShopCorp/ps_checkout/security/advisories/GHSA-54hq-mf6h-48xh - () https://github.com/PrestaShopCorp/ps_checkout/security/advisories/GHSA-54hq-mf6h-48xh - Patch, Vendor Advisory
CPE cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:*

17 Oct 2025, 14:15

Type Values Removed Values Added
Summary (en) PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist. (en) PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

16 Oct 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-16 18:15

Updated : 2025-12-29 20:06


NVD link : CVE-2025-61922

Mitre link : CVE-2025-61922

CVE.ORG link : CVE-2025-61922


JSON object : View

Products Affected

prestashop

  • prestashop_checkout
CWE
CWE-287

Improper Authentication