CVE-2023-48926: Prestashop Advanced Loyalty Program

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.

Affected products

  • Prestashop Advanced Loyalty Program: before 2.3.4 (fixed in 2.3.4)

Published 2024-01-16. Last modified 2026-06-17.