PrestaShop Checkout allows customer account takeover via email
Critical severity
GitHub Reviewed
Published
Oct 16, 2025
in
PrestaShopCorp/ps_checkout
•
Updated Oct 17, 2025
Package
Affected versions
>= 5.0.0, < 5.0.5
>= 1.3.0, < 4.4.1
Patched versions
5.0.5
4.4.1
Description
Published by the National Vulnerability Database
Oct 16, 2025
Published to the GitHub Advisory Database
Oct 16, 2025
Reviewed
Oct 16, 2025
Last updated
Oct 17, 2025
Impact
Missing validation on Express Checkout feature allows silent log-in
Affected versions
The issue was introduced in PrestaShop Checkout 1.3.0 .
All versions above 1.3.0 are vulnerable except of course the patch versions published on 16/10/2025: 7.4.4.1, 8.4.4.1, 7.5.0.5, 8.5.0.5, 9.5.0.5
Patches
The problem has been patched in versions
Read our Versioning policy to learn more about our build numbers and versions of PrestaShop Checkout
Credits
We would like to thank Léo CUNÉAZ for reporting the issue.
References