CVE-2025-7808: WP Shopify < 1.5.4 - Reflected XSS
The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7808?
CVE-2025-7808 is classified as a high severity vulnerability due to its potential impact on high privilege users.
How do I fix CVE-2025-7808?
To mitigate CVE-2025-7808, update the WP Shopify plugin to version 1.5.4 or later, which includes the necessary fixes.
What types of attacks can CVE-2025-7808 be exploited for?
CVE-2025-7808 can be exploited for Reflected Cross-Site Scripting (XSS) attacks, affecting high privilege WordPress users.
Who is affected by CVE-2025-7808?
CVE-2025-7808 affects all versions of the WP Shopify plugin prior to 1.5.4.
What should I do if I cannot update to fix CVE-2025-7808?
If you cannot update, consider disabling the WP Shopify plugin until a fix can be applied to prevent potential exploitation.