CVE-2025-24558: WordPress CRM Perks plugin <= 1.1.5 - Reflected Cross Site Scripting (XSS) vulnerability
Published Feb 14, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks support-x allows Reflected XSS.This issue affects CRM Perks: from n/a through <= 1.1.5.
Affected Software
1 affected component
CRM Perks WordPress CRM Perks plugin<=1.1.5
Remediation
Information
Update the WordPress CRM Perks plugin to the latest available version (at least 1.1.6).
Event History
Feb 14, 2025
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24558?
CVE-2025-24558 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-24558?
To fix CVE-2025-24558, you should update the CRM Perks plugin to the latest version beyond 1.1.5.
3
What software is affected by CVE-2025-24558?
CVE-2025-24558 affects CRM Perks versions up to and including 1.1.5.
4
Can CVE-2025-24558 be exploited remotely?
Yes, CVE-2025-24558 can be exploited remotely through a web browser.
5
What is the potential impact of CVE-2025-24558?
The potential impact of CVE-2025-24558 includes unauthorized access to user data and session hijacking.