External risk intelligence

PrestaShop Checkout Silent Login Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-61922

The vulnerability resides in a payment module for PrestaShop, an e-commerce platform. Payment modules and checkout features are designed to be public-facing to process transactions from internet users. Because this functionality is inherently exposed to the public internet for normal business operations, it is considered very likely to be reachable.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in the PrestaShop Checkout payment module. This issue, affecting specific versions of the module, allows for unauthorized account takeover through a flawed Express Checkout feature. The primary concern is confirming if your environment utilizes the affected module and versions, as the potential for compromise is significant.

  • Silent logins allow account takeover.
  • Protects customer data and trust.
  • Confirm module and version relevance.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by leveraging the exposed Express Checkout feature in PrestaShop's official payment module. Without proper validation, an attacker can silently log into a user's account using only their email address, leading to account takeover.

  • Publicly accessible payment module.
  • Missing validation in Express Checkout.
  • Account takeover via email.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the PrestaShop Checkout module could allow an attacker to silently log in as a user when the Express Checkout feature is enabled. This could lead to account takeover through the user's email address, potentially affecting user account data and service behavior.

  • User account data at risk.
  • Silent login via email and checkout.
  • Account takeover and unauthorized access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the PrestaShop Checkout module likely impacts e-commerce site administrators and platform teams responsible for managing payment integrations. The first step is to identify all instances of the affected module, assess their reachability and business criticality, and then prioritize remediation efforts based on risk.

  • Module owners should drive remediation.
  • Verify module reachability and impact.
  • Plan and execute secure updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PrestaShop Checkout?

PrestaShop Checkout is the official payment processing module for the PrestaShop e-commerce platform. It integrates directly with PayPal to handle financial transactions for online stores. This module acts as a bridge between the customer and the payment provider, managing the data exchange required to complete purchases securely on your website.

How does CVE-2025-61922 enable account takeover?

This vulnerability is classified as CWE-287, or Improper Authentication. The module fails to correctly validate user credentials during the Express Checkout process. Because this check is missing, an attacker can bypass standard login security and silently access a user's account simply by providing the target's email address.

What triggers this authentication flaw?

The issue is triggered specifically through the Express Checkout feature within the payment module. It is not a general flaw in the entire site's login system. If the Express Checkout function is disabled or not in use, this specific authentication bypass path is not active.

Do I need to worry if my site is internal?

According to Halo Surface Signal, this vulnerability is considered very likely to be reachable. Since payment modules are fundamentally designed to interact with the public internet to process customer transactions, they are almost always internet-facing. If your store is accessible to customers online, you should consider this a high-priority concern.

How do I secure my site against this vulnerability?

Your first step is to audit your PrestaShop environment to see if you are using the vulnerable versions of the PrestaShop Checkout module. Once identified, you should prioritize updating the module to the patched versions specified in the advisory. Since there are no workarounds, applying the official update is the only way to resolve the flaw.

References