VYPR
Medium severity6.5NVD Advisory· Published Dec 9, 2025· Updated Apr 15, 2026

CVE-2025-67544

CVE-2025-67544

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Shopkeeper Extender shopkeeper-extender allows Stored XSS.This issue affects Shopkeeper Extender: from n/a through < 7.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stored cross-site scripting vulnerability in Shopkeeper Extender before 7.0 lets attackers inject malicious scripts executed when visitors view pages, requiring privileged user interaction.

The Shopkeeper Extender plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability caused by improper neutralization of input during web page generation [1]. This issue affects versions from n/a through before 7.0 [1].

Exploitation

An attacker with a privileged role—such as an editor or administrator—can inject arbitrary scripts into the plugin's input fields [1]. Successful exploitation requires a privileged user to perform an action, such as clicking a crafted link or submitting a form, thereby storing the payload in the database [1].

Impact

When a victim visits a page containing the stored payload, the malicious script executes in their browser [1]. This could allow redirection to malicious sites, injection of advertisements, theft of session cookies, or defacement of the website [1]. The plugin's wide adoption means this vulnerability could be used in mass-exploit campaigns targeting thousands of websites [1].

Mitigation

The vendor has released version 7.0 which fixes the issue [1]. Users are advised to update immediately or enable auto-update via Patchstack [1]. If unable to update, contact a hosting provider or web developer for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.