CVE-2025-11888

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it possible for authenticated attackers, with Editor-level access and above, to activate and deactivate licenses.


We have discovered 3,092 live websites that are affected by CVE-2025-11888.

Run a Free Instant Scan




Affected Software

Product  Shopengine
Category Wordpress Plugins
Vulnerable Domains3,092 live websites (71% of Shopengine install base)
Vulnerable Versions
  • from 0 through 4.8.4
Vulnerable Versions Count44 versions ( 94% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Oct 25, 2025
  • Updated - Oct 27, 2025

Credits

  • Jonas Benjamin Friedli (finder)

Website Distribution by Country

Number of websites using CVE-2025-11888
United States658 websites



France251 websites
Germany207 websites
Brazil192 websites
Italy149 websites
GB143 websites
Cyprus114 websites
India112 websites
South Africa93 websites
Poland86 websites

Website Distribution by TLD

Number of websites using CVE-2025-11888
.com1,370 websites
.com.br187 websites
.fr120 websites
.it106 websites
.co.uk71 websites
.pl69 websites
.org58 websites
.ru52 websites
.net52 websites
.com.au48 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-11888

Top websites that are affected by CVE-2025-11888. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com Bangladesh**,***
****.com Thailand***,***
********.com Thailand***,***
*********.com United States***,***
*********.it Germany***,***
***************.org France***,***
**********************.com France***,***
********.***.vn Vietnam*,***,***
******.de Germany*,***,***
***.eu Germany*,***,***
See full domain list

FAQ

CVE-2025-11888 is Incorrect Authorization in Shopengine
A total of 3,092 websites have been identified as vulnerable to CVE-2025-11888, based on global website indexing conducted by WebTechSurvey.
The Shopengine is affected by the CVE-2025-11888 vulnerability.
Shopengine versions up to and including 4.8.4 are vulnerable to CVE-2025-11888.