Unauthorized Data Modification in ShopEngine Elementor WooCommerce Builder Addon
CVE-2025-11888

2.7LOW

What is CVE-2025-11888?

The ShopEngine Elementor WooCommerce Builder Addon for WordPress contains a vulnerability that allows authenticated users with Editor-level access and above to modify plugin settings by activating or deactivating licenses without proper authorization checks. This issue arises from insufficient capability verifications in the post_deactive() and post_activate() functions, affecting all versions up to and including 4.8.4.

Affected Version(s)

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution * <= 4.8.4

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-11888 : Unauthorized Data Modification in ShopEngine Elementor WooCommerce Builder Addon