The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it possible for authenticated attackers, with Editor-level access and above, to activate and deactivate licenses.
We have discovered 3,092 live websites that are affected by CVE-2025-11888.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 3,092 live websites (71% of Shopengine install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 44 versions ( 94% of all versions) |
| 658 websites | |
| 251 websites | |
| 207 websites | |
| 192 websites | |
| 149 websites | |
| 143 websites | |
| 114 websites | |
| 112 websites | |
| 93 websites | |
| 86 websites |
| .com | 1,370 websites |
| .com.br | 187 websites |
| .fr | 120 websites |
| .it | 106 websites |
| .co.uk | 71 websites |
| .pl | 69 websites |
| .org | 58 websites |
| .ru | 52 websites |
| .net | 52 websites |
| .com.au | 48 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | **,*** | ||
| ****.com | ***,*** | ||
| ********.com | ***,*** | ||
| *********.com | ***,*** | ||
| *********.it | ***,*** | ||
| ***************.org | ***,*** | ||
| **********************.com | ***,*** | ||
| ********.***.vn | *,***,*** | ||
| ******.de | *,***,*** | ||
| ***.eu | *,***,*** |
FAQ