---
id: CVE-2025-61924
title: >-
  PrestaShop Checkout is the PrestaShop official payment module in partnership
  with PayPal
summary: >-
  PrestaShop Checkout is the PrestaShop official payment module in partnership
  with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant
  account hijacking from backoffice due to wrong usage of the PHP
  array_search(). Th…
severity: low
cvss: 3.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-184
vendor: prestashop
product: prestashop_checkout
affected:
  - prestashop_checkout < 7.4.4.1
  - 'prestashop_checkout >= 7.5.0.1, < 7.5.0.5'
  - 'prestashop_checkout >= 8.3.1.0, < 8.4.4.1'
  - 'prestashop_checkout >= 8.5.0.0, < 8.5.0.5'
  - 'prestashop_checkout >= 9.4.3.1, < 9.5.0.5'
patched:
  - prestashop_checkout 9.5.0.5
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61924'
references:
  - url: >-
      https://github.com/PrestaShopCorp/ps_checkout/security/advisories/GHSA-wvpg-4wrh-5889
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00269
epssPercentile: 0.17527
ingestedAt: '2026-10-09T12:53:29.050Z'
---

## Overview

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

## Affected

- `prestashop_checkout < 7.4.4.1`
- `prestashop_checkout >= 7.5.0.1, < 7.5.0.5`
- `prestashop_checkout >= 8.3.1.0, < 8.4.4.1`
- `prestashop_checkout >= 8.5.0.0, < 8.5.0.5`
- `prestashop_checkout >= 9.4.3.1, < 9.5.0.5`

## Remediation

Upgrade past the affected range:

- `prestashop_checkout 9.5.0.5`
