CVE Vulnerabilities

CVE-2025-61922

Improper Authentication

Published: Oct 16, 2025 | Modified: Dec 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Prestashop_checkout Prestashop 1.3.0 (including) 7.4.4.1 (excluding)
Prestashop_checkout Prestashop 7.5.0.1 (including) 7.5.0.5 (excluding)
Prestashop_checkout Prestashop 8.3.1.0 (including) 8.4.4.1 (excluding)
Prestashop_checkout Prestashop 8.5.0.0 (including) 8.5.0.5 (excluding)
Prestashop_checkout Prestashop 9.4.3.1 (including) 9.5.0.5 (excluding)

Potential Mitigations

References