CVE-2025-67544
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Shopkeeper Extender shopkeeper-extender allows Stored XSS.This issue affects Shopkeeper Extender: from n/a through < 7.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stored cross-site scripting vulnerability in Shopkeeper Extender before 7.0 lets attackers inject malicious scripts executed when visitors view pages, requiring privileged user interaction.
The Shopkeeper Extender plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability caused by improper neutralization of input during web page generation [1]. This issue affects versions from n/a through before 7.0 [1].
Exploitation
An attacker with a privileged role—such as an editor or administrator—can inject arbitrary scripts into the plugin's input fields [1]. Successful exploitation requires a privileged user to perform an action, such as clicking a crafted link or submitting a form, thereby storing the payload in the database [1].
Impact
When a victim visits a page containing the stored payload, the malicious script executes in their browser [1]. This could allow redirection to malicious sites, injection of advertisements, theft of session cookies, or defacement of the website [1]. The plugin's wide adoption means this vulnerability could be used in mass-exploit campaigns targeting thousands of websites [1].
Mitigation
The vendor has released version 7.0 which fixes the issue [1]. Users are advised to update immediately or enable auto-update via Patchstack [1]. If unable to update, contact a hosting provider or web developer for assistance [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <7.0
- Range: < 7.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.