Omnishop <= 1.0.9 - Cross-Site Request Forgery to Arbitrary User Deletion via /users/delete REST Endpoint
medium
The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all versions up to, and including, 1.0.9. The route’s permission_callback only verifies that the requester is logged in, but fails to require any nonce or other proof of intent. This makes it possible for un...
- CVSS:
- 6.5
- Affected:
- up to 1.0.9
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2025
CVE-2025-6214 on NVD →
Omnishop <= 1.0.9 - Missing Registration Restriction to Unauthenticated Account Creation via /users/register REST Endpoint
medium
The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/register endpoint is exposed to the public (permission_callback always returns true) and invokes wp_create_user() unconditionally, ignoring the site’s users_can_register option...
- CVSS:
- 5.3
- Affected:
- up to 1.0.9
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2025
CVE-2025-6215 on NVD →
Omnishop – Mobile shop apps complementing your WooCommerce webshop [omnishop] <= 1.0.9 (unfixed + closed)
unknown
- Affected:
- up to 1.0.9
- Fix:
- No patched version reported
CVE-2025-6214 on NVD →
Omnishop – Mobile shop apps complementing your WooCommerce webshop [omnishop] <= 1.0.9 (unfixed + closed)
unknown
- Affected:
- up to 1.0.9
- Fix:
- No patched version reported
CVE-2025-6215 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database