CVE-2025-24559: WordPress WP Mailster plugin <= 1.8.15.0 - Reflected Cross Site Scripting (XSS) vulnerability
Published Feb 3, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.This issue affects WP Mailster: from n/a through <= 1.8.15.0.
Affected Software
2 affected components
Wpmailster Wp Mailster Wordpress<1.8.16
brandtoss WP Mailster>=n/a<1.8.15.0
Event History
Feb 3, 2025
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24559?
CVE-2025-24559 is a reflected Cross-site Scripting (XSS) vulnerability that can lead to significant security issues if exploited.
2
How do I fix CVE-2025-24559?
To fix CVE-2025-24559, update the WP Mailster plugin to version 1.8.16 or later.
3
What versions of WP Mailster are affected by CVE-2025-24559?
CVE-2025-24559 affects WP Mailster versions from n/a through 1.8.15.0.
4
What are the consequences of exploiting CVE-2025-24559?
Exploitation of CVE-2025-24559 could allow attackers to execute arbitrary scripts in the context of the user's browser.
5
Who is the vendor responsible for CVE-2025-24559?
The vendor responsible for the affected software in CVE-2025-24559 is Brandtoss.