PT-2025-42516 · Prestashop · Prestashop Checkout

Inem0O

·

Published

2025-10-16

·

Updated

2025-12-29

·

CVE-2025-61924

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop Checkout versions prior to 4.4.1 and 5.0.5
Description A flaw exists in the PrestaShop Checkout module due to incorrect use of the PHP array search() function. This improper usage allows bypassing validation, potentially leading to the hijacking of the Target PayPal merchant account from the backoffice.
Recommendations Update to PrestaShop Checkout version 4.4.1 for PrestaShop 1.7 and 8. Update to PrestaShop Checkout version 5.0.5 for PrestaShop 1.7, 8, and 9.

Exploit

Fix

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

CVE-2025-61924
GHSA-WVPG-4WRH-5889

Affected Products

Prestashop Checkout