---
id: CVE-2025-61922
title: >-
  PrestaShop Checkout is the PrestaShop official payment module in partnership
  with PayPal
summary: >-
  PrestaShop Checkout is the PrestaShop official payment module in partnership
  with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5,
  missing validation on the Express Checkout feature allows silent login,
  enabling a…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-287
vendor: prestashop
product: prestashop_checkout
affected:
  - 'prestashop_checkout >= 1.3.0, < 7.4.4.1'
  - 'prestashop_checkout >= 7.5.0.1, < 7.5.0.5'
  - 'prestashop_checkout >= 8.3.1.0, < 8.4.4.1'
  - 'prestashop_checkout >= 8.5.0.0, < 8.5.0.5'
  - 'prestashop_checkout >= 9.4.3.1, < 9.5.0.5'
patched:
  - prestashop_checkout 9.5.0.5
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61922'
references:
  - url: >-
      https://github.com/PrestaShopCorp/ps_checkout/security/advisories/GHSA-54hq-mf6h-48xh
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
epss: 0.00503
epssPercentile: 0.41084
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/g0vguy/CVE-2025-61922-PoC'
    - 'https://github.com/captaincookie34/Vulnerability-Playground-CVE-2025-61922'
  checkedAt: '2026-10-09T12:54:06.036Z'
exploitAvailable: true
ingestedAt: '2026-10-09T12:53:29.040Z'
---

## Overview

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

## Affected

- `prestashop_checkout >= 1.3.0, < 7.4.4.1`
- `prestashop_checkout >= 7.5.0.1, < 7.5.0.5`
- `prestashop_checkout >= 8.3.1.0, < 8.4.4.1`
- `prestashop_checkout >= 8.5.0.0, < 8.5.0.5`
- `prestashop_checkout >= 9.4.3.1, < 9.5.0.5`

## Remediation

Upgrade past the affected range:

- `prestashop_checkout 9.5.0.5`
