CVE-2025-24626: WordPress Music Store – WordPress eCommerce Plugin <= 1.1.19 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jan 27, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Music Store music-store allows Reflected XSS.This issue affects Music Store: from n/a through <= 1.1.19.
Affected Software
1 affected component
CodePeople WordPress Music Store<=1.1.19
Remediation
Information
Update the WordPress Music Store wordpress plugin to the latest available version (at least 1.2.0).
Event History
Jan 27, 2025
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24626?
CVE-2025-24626 is classified as a medium severity Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-24626?
To fix CVE-2025-24626, update CodePeople Music Store to version 1.1.20 or later.
3
What types of attacks can CVE-2025-24626 potentially enable?
CVE-2025-24626 can potentially enable reflected XSS attacks that may lead to unauthorized actions being performed on behalf of users.
4
Which software versions are affected by CVE-2025-24626?
CVE-2025-24626 affects CodePeople Music Store versions up to and including 1.1.19.
5
Is CVE-2025-24626 present in WordPress Music Store as well?
Yes, CVE-2025-24626 also affects the WordPress Music Store plugin versions up to and including 1.1.19.