First published: Fri Jan 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Event post allows Stored XSS. This issue affects Event post: from n/a through 5.9.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
N.O.U.S. Open Useful and Simple Event post | <=5.9.7 | |
WordPress Event post plugin | <=5.9.7 |
Update the WordPress Event post wordpress plugin to the latest available version (at least 5.9.8).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24585 is classified as a high severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
To fix CVE-2025-24585, upgrade N.O.U.S. Open Useful and Simple Event post or the WordPress Event post plugin to version 5.9.8 or later.
The impact of CVE-2025-24585 includes the risk of attackers injecting malicious scripts through stored XSS, potentially compromising user data and site integrity.
CVE-2025-24585 affects N.O.U.S. Open Useful and Simple Event post and WordPress Event post plugin versions up to and including 5.9.7.
Using a firewall may provide some protection, but it is not a complete safeguard against CVE-2025-24585; updating to the latest software version is essential.