Privilege Escalation in EasyCommerce WordPress Ecommerce Plugin
CVE-2025-11457

9.8CRITICAL

What is CVE-2025-11457?

The EasyCommerce plugin for WordPress is susceptible to a Privilege Escalation vulnerability due to improper access controls on the /easycommerce/v1/orders REST API endpoint. This flaw allows users without authentication to manipulate role assignments during registration, potentially granting them administrator privileges. Exploitation of this vulnerability can lead to unauthorized access, compromising the security and integrity of affected WordPress sites.

Affected Version(s)

EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin * <= 1.5.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.