CVE-2025-24617: WordPress AcyMailing Plugin < 9.11.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Reflected XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through < 9.11.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24617?
CVE-2025-24617 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-24617?
To fix CVE-2025-24617, update the AcyMailing SMTP Newsletter to the latest version provided by the vendor.
What software is affected by CVE-2025-24617?
CVE-2025-24617 affects AcyMailing SMTP Newsletter and the WordPress AcyMailing Plugin up to version 9.11.1.
What does reflected XSS mean in the context of CVE-2025-24617?
Reflected XSS in CVE-2025-24617 means that an attacker can inject malicious scripts that are executed immediately upon a user's interaction with a crafted URL.
Is there a workaround for CVE-2025-24617 if I cannot update right away?
A temporary workaround for CVE-2025-24617 may involve sanitizing user inputs to prevent the execution of malicious scripts.