PT-2025-19909 · WordPress · Wpshop 2

·

CVE-2025-3853

·

Published

2025-05-07

·

Updated

2025-05-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPshop 2 – E-Commerce plugin for WordPress versions 2.0.0 through 2.6.0
Description The issue allows authenticated attackers with Subscriber-level access and above to create valid API keys on behalf of other users due to missing validation on a user-controlled key in the callback generate api key() function.
Recommendations For versions 2.0.0 through 2.6.0, consider disabling the callback generate api key() function until a patch is available to prevent the creation of unauthorized API keys. Restrict access to API key generation to minimize the risk of exploitation.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3853

Affected Products

Wpshop 2