CVE-2025-6215 | Omnishop Plugin up to 1.0.9 on WordPress REST Endpoint /users/register wp_create_user Remote Code Execution
A vulnerability was found in Omnishop Plugin up to 1.0.9 on WordPress. It has been classified as critical. Affected is the function wp_create_user of the file /users/register of the component REST Endpoint. The manipulation leads to Remote Code Execution.
This vulnerability is traded as CVE-2025-6215. It is possible to launch the attack remotely. There is no exploit available.