CVE-2025-11457 | EasyCommerce Plugin up to 1.5.0 on WordPress REST API Endpoint /easycommerce/v1/orders privileges management
A vulnerability was found in EasyCommerce Plugin up to 1.5.0 on WordPress. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /easycommerce/v1/orders of the component REST API Endpoint. Such manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2025-11457. The attack may be launched remotely. There is no exploit available.