CVE-2025-11888 LOW

CVE-2025-11888: ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update

Vendor Roxnor
Product ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution
Weakness CWE-863 · Incorrect authorization
Published October 25, 2025
Last update April 8, 2026

CVSS base score

2.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it possible for authenticated attackers, with Editor-level access and above, to activate and deactivate licenses.

Explanation of Vulnerability in Simple Terms

02Summary

ShopEngine Elementor WooCommerce Builder Addon versions up to 4.8.4 contain an authorization flaw that allows high-privilege users to make unintended modifications. The vulnerability requires administrator-level access and does not expose sensitive data or disrupt site availability. Site owners should update to a version newer than 4.8.4 when available.

What an attacker can do

03Attacker Capabilities

A high-privilege user can make unauthorized modifications to site data.

Potential impact on your site

04Site Impact

Admins with compromised credentials could alter site content or settings beyond their intended scope.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level access to the WordPress site.

Key dates

06Disclosure timeline

October 25, 2025 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE