CVE-2025-6215: Omnishop – Mobile Shop Apps Complementing Your Woocommerce Webshop
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/register endpoint is exposed to the public (permission_callback always returns true) and invokes wp_create_user() unconditionally, ignoring the site’s users_can_register option and any nonce or CAPTCHA checks. This makes it possible for unauthenticated attackers to create arbitrary user accounts (customer) on sites where registrations should be closed.
Affected products
- Omnishop Omnishop – Mobile Shop Apps Complementing Your Woocommerce Webshop: up to and including 1.0.9
Published 2025-07-23. Last modified 2026-06-17.