PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
History

Tue, 21 Oct 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Prestashop
Prestashop prestashop
Prestashopcorp
Prestashopcorp checkout
Vendors & Products Prestashop
Prestashop prestashop
Prestashopcorp
Prestashopcorp checkout

Fri, 17 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Description PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist. PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

Thu, 16 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Oct 2025 17:45:00 +0000

Type Values Removed Values Added
Description PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
Title PrestaShop Checkout allows customer account takeover via email
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-16T17:26:14.999Z

Updated: 2025-10-17T14:00:38.840Z

Reserved: 2025-10-03T22:21:59.615Z

Link: CVE-2025-61922

cve-icon Vulnrichment

Updated: 2025-10-16T18:28:44.460Z

cve-icon NVD

Status : Received

Published: 2025-10-16T18:15:38.597

Modified: 2025-10-17T14:15:47.737

Link: CVE-2025-61922

cve-icon Redhat

No data.