CVE-2025-67557 Overview
CVE-2025-67557 is a stored cross-site scripting (XSS) vulnerability in the Rhys Wynne WP eBay Product Feeds plugin (ebay-feeds-for-wordpress) for WordPress. The flaw stems from improper neutralization of user input during web page generation [CWE-79]. All plugin versions up to and including 3.4.9 are affected. An authenticated attacker with high privileges can inject malicious scripts that persist in the application and execute in victim browsers when they view affected pages. Successful exploitation can lead to session theft, administrative action abuse, and redirection to attacker-controlled infrastructure.
Critical Impact
Stored XSS enables persistent script execution in administrator and visitor browsers, with scope change allowing impact beyond the vulnerable component.
Affected Products
- WP eBay Product Feeds plugin (ebay-feeds-for-wordpress) version 3.4.9 and earlier
- WordPress installations using the Rhys Wynne WP eBay Product Feeds plugin
- Any WordPress site rendering plugin-generated content to administrators or visitors
Discovery Timeline
- 2025-12-09 - CVE-2025-67557 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-67557
Vulnerability Analysis
The vulnerability is a stored XSS flaw in the WP eBay Product Feeds plugin. The plugin fails to properly sanitize and escape user-supplied input before storing it and rendering it back into HTML output. An attacker with high privileges on the WordPress instance can submit crafted input containing JavaScript payloads. These payloads persist in the database and execute whenever a user loads a page containing the stored content.
The CVSS vector indicates a scope change, meaning the injected script can affect resources beyond the vulnerable plugin itself. User interaction is required, as a victim must view the affected page for the payload to execute. The impact covers confidentiality, integrity, and availability at a low level across the broader WordPress environment.
Root Cause
The root cause is missing or insufficient output encoding and input sanitization in plugin code that handles administrative inputs. WordPress provides helpers such as esc_html(), esc_attr(), wp_kses_post(), and sanitize_text_field() to neutralize dangerous characters. The plugin does not apply these consistently to input stored and later echoed back into page markup.
Attack Vector
Exploitation is network-based and requires an authenticated account with high privileges on the target WordPress site. The attacker submits a crafted payload through a plugin form or configuration field. The payload is stored in the WordPress database. When any user, including a logged-in administrator, renders a page that displays the stored value, the script executes in their browser session. Review the Patchstack Vulnerability Report for additional advisory context.
// No verified public exploit code is available for CVE-2025-67557.
// Refer to the Patchstack advisory for technical details.
Detection Methods for CVE-2025-67557
Indicators of Compromise
- Unexpected <script>, onerror, onload, or javascript: strings stored in WordPress database tables related to the WP eBay Product Feeds plugin
- Outbound browser connections from administrator sessions to unknown domains after visiting plugin-managed pages
- New or altered WordPress administrator accounts created shortly after visits to plugin pages
- Unusual AJAX requests to wp-admin/admin-ajax.php originating from administrator browsers
Detection Strategies
- Query the wp_options, wp_postmeta, and plugin-specific tables for HTML or script tags in fields that should contain plain text
- Deploy a web application firewall rule that flags payloads containing event handler attributes targeting plugin endpoints
- Review WordPress audit logs for high-privilege users submitting unusual values to plugin configuration forms
Monitoring Recommendations
- Enable continuous monitoring of WordPress plugin update feeds and the Patchstack advisory database for new disclosures
- Monitor browser Content Security Policy (CSP) violation reports to catch unexpected inline script execution
- Alert on changes to privileged WordPress accounts and session cookies originating from plugin-rendered pages
How to Mitigate CVE-2025-67557
Immediate Actions Required
- Audit WordPress installations for the presence of the WP eBay Product Feeds plugin at version 3.4.9 or earlier
- Restrict access to high-privilege WordPress accounts and enforce multi-factor authentication on all administrator logins
- Review plugin configuration fields and database entries for suspicious script content and remove any confirmed payloads
- Rotate session cookies and administrator credentials if exploitation is suspected
Patch Information
At the time of publication, the advisory lists all versions up to and including 3.4.9 as affected. Monitor the Patchstack Vulnerability Report and the WordPress plugin repository for an upstream fix. Apply the vendor patch as soon as a fixed release becomes available.
Workarounds
- Deactivate and remove the WP eBay Product Feeds plugin until a patched version is released
- Implement a strict Content Security Policy that blocks inline scripts and restricts script sources to trusted origins
- Place the WordPress admin interface behind an IP allowlist or VPN to reduce attacker reach
# Example: temporarily deactivate the plugin using WP-CLI
wp plugin deactivate ebay-feeds-for-wordpress
wp plugin uninstall ebay-feeds-for-wordpress
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.