VYPR
High severity7.1NVD Advisory· Published Mar 28, 2025· Updated Apr 23, 2026

CVE-2025-22767

CVE-2025-22767

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommerce allows Reflected XSS.This issue affects GlobalPayments WooCommerce: from n/a through <= 1.13.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in GlobalPayments WooCommerce plugin (≤1.13.2) allows attackers to inject malicious scripts via crafted links, requiring user interaction.

The GlobalPayments WooCommerce plugin for WordPress suffers from a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This flaw affects all versions up to and including 1.13.2, and is classified as a high-severity issue with a CVSS v3 score of 7.1.

Exploitation requires an attacker to craft a malicious link that, when clicked by a privileged user (such as an administrator), reflects the injected script into the page output. No direct authentication is needed for the attacker, but the victim must be logged into the WordPress admin panel for the attack to succeed. This type of vulnerability is commonly used in mass-exploit campaigns targeting thousands of sites simultaneously [1].

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the context of the affected site. This can lead to session hijacking, redirection to malicious websites, injection of advertisements, or other HTML payloads that compromise the integrity of the site and its visitors [1].

The vendor has released version 1.13.3, which resolves the vulnerability. Users are strongly advised to update immediately. For those unable to update, Patchstack provides a mitigation rule that blocks attacks until the patch is applied [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.