Privilege Escalation in EasyCommerce WordPress Ecommerce Plugin
CVE-2025-11457
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 November 2025
What is CVE-2025-11457?
The EasyCommerce plugin for WordPress is susceptible to a Privilege Escalation vulnerability due to improper access controls on the /easycommerce/v1/orders REST API endpoint. This flaw allows users without authentication to manipulate role assignments during registration, potentially granting them administrator privileges. Exploitation of this vulnerability can lead to unauthorized access, compromising the security and integrity of affected WordPress sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EasyCommerce β AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin * <= 1.5.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved