Vulnerability Description
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.6.0 via the callback_generate_api_key() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create valid API keys on behalf of other users.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/wpshop/tags/2.6.0/modules/api/action/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/136d63c4-c985-413f-8d8
FAQ
What is CVE-2025-3853?
CVE-2025-3853 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.6.0 via the callback_generate_api_key() due to missing validation on a user cont...
How severe is CVE-2025-3853?
CVE-2025-3853 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-3853?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.