CVE-2025-11888: ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the postdeactive() function and postactivate() function in all versions up to, and including, 4.8.4. This makes it possible for authenticated attackers, with Editor-level access and above, to activate and deactivate licenses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11888?
CVE-2025-11888 has a medium severity rating due to the potential for unauthorized data modification.
How do I fix CVE-2025-11888?
To fix CVE-2025-11888, update the ShopEngine Elementor WooCommerce Builder Addon to version 4.8.5 or later.
What versions are affected by CVE-2025-11888?
All versions of the ShopEngine Elementor WooCommerce Builder Addon up to and including 4.8.4 are affected by CVE-2025-11888.
What functionalities are impacted by CVE-2025-11888?
CVE-2025-11888 impacts the post_deactive() and post_activate() functions due to an insufficient capability check.
Is CVE-2025-11888 being actively exploited?
As of now, there is no public indication that CVE-2025-11888 is being actively exploited.