CVE-2025-24631: WordPress BP Email Assign Templates Plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Reflected XSS.This issue affects BP Email Assign Templates: from n/a through <= 1.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24631?
CVE-2025-24631 is classified as a reflected cross-site scripting (XSS) vulnerability, which can significantly impact user security.
How do I fix CVE-2025-24631?
To fix CVE-2025-24631, you should upgrade the PhiloPress BP Email Assign Templates plugin to a version later than 1.5.
What software is affected by CVE-2025-24631?
CVE-2025-24631 affects the PhiloPress BP Email Assign Templates plugin versions up to and including 1.5.
Can CVE-2025-24631 lead to data theft?
Yes, CVE-2025-24631 can potentially lead to data theft through malicious script execution in users' browsers.
What is reflected XSS as seen in CVE-2025-24631?
Reflected XSS in CVE-2025-24631 occurs when user input is included in web page responses, allowing attackers to execute scripts in the context of a user's session.