CVE-2025-11457 PUBLISHED

EasyCommerce – AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin 0.9.0-beta2 - 1.5.0 - Unauthenticated Privilege Escalation

Assigner: Wordfence
Reserved: 07.10.2025 Published: 11.11.2025 Updated: 14.11.2025

The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9.0-beta2 to 1.5.0. This is due to the /easycommerce/v1/orders REST API endpoint not properly restricting the ability for users to select roles during registration. This makes it possible for unauthenticated attackers to gain administrator-level access to a vulnerable site.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor easycommerce
Product EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin
Versions Default: unaffected
  • affected from * to 1.5.0 (incl.)

Credits

  • Kenneth Dunn finder

References

Problem Types

  • CWE-269 Improper Privilege Management CWE