plugin

Omnishop Vulnerabilities

4 known security issues reported for the Omnishop WordPress plugin. Most recent disclosed Jul 22, 2025.

2 medium

Running Omnishop on your site? Check whether your installed version is affected.

Scan your site free

Omnishop <= 1.0.9 - Cross-Site Request Forgery to Arbitrary User Deletion via /users/delete REST Endpoint

medium

The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all versions up to, and including, 1.0.9. The route’s permission_callback only verifies that the requester is logged in, but fails to require any nonce or other proof of intent. This makes it possible for un...

CVSS:
6.5
Affected:
up to 1.0.9
Fix:
No patched version reported
Disclosed:
Jul 22, 2025

CVE-2025-6214 on NVD →

Omnishop <= 1.0.9 - Missing Registration Restriction to Unauthenticated Account Creation via /users/register REST Endpoint

medium

The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/register endpoint is exposed to the public (permission_callback always returns true) and invokes wp_create_user() unconditionally, ignoring the site’s users_can_register option...

CVSS:
5.3
Affected:
up to 1.0.9
Fix:
No patched version reported
Disclosed:
Jul 22, 2025

CVE-2025-6215 on NVD →

Omnishop &#8211; Mobile shop apps complementing your WooCommerce webshop [omnishop] <= 1.0.9 (unfixed + closed)

unknown
Affected:
up to 1.0.9
Fix:
No patched version reported

CVE-2025-6214 on NVD →

Omnishop &#8211; Mobile shop apps complementing your WooCommerce webshop [omnishop] <= 1.0.9 (unfixed + closed)

unknown
Affected:
up to 1.0.9
Fix:
No patched version reported

CVE-2025-6215 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database