CVE-2025-3852 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to the plugin…
High CVSS: 8.8

CVE-2025-3852

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email & password through the update() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Vendor
-
Product
-
CWE
CWE-269
Yayın Tarihi
2025-05-07 03:15:17
Güncelleme
2025-05-07 14:13:20
Source Identifier
security@wordfence.com
KEV Date Added
-

Kategoriler

Referanslar