CVE-2025-61924

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/10/2025
Last modified:
29/12/2025

Description

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:* 7.4.4.1 (excluding)
cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:* 7.5.0.1 (including) 7.5.0.5 (excluding)
cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:* 8.3.1.0 (including) 8.4.4.1 (excluding)
cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:* 8.5.0.0 (including) 8.5.0.5 (excluding)
cpe:2.3:a:prestashop:prestashop_checkout:*:*:*:*:*:prestashop:*:* 9.4.3.1 (including) 9.5.0.5 (excluding)