In the world of e-commerce, payment and checkout forms are a sensitive target for cyber attacks. A vulnerability CVE-2025-61922 affecting the official PrestaShop Checkout module, developed in collaboration with PayPal, was recently made public. This flaw allows a customer account takeover without visible interaction ("silent login"). In this article we analyze what it is, what the implications are for those running a PrestaShop-based store, and what immediate countermeasures to take.