First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Wishlist allows Reflected XSS. This issue affects Wishlist: from n/a through 1.0.39.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wishlist | <=1.0.39 | |
Wishlist | <=1.0.39 |
Update the WordPress Wishlist wordpress plugin to the latest available version (at least 1.0.40).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24655 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-24655, upgrade the PickPlugins Wishlist to version 1.0.40 or later.
CVE-2025-24655 enables reflected cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
CVE-2025-24655 affects all versions of the PickPlugins Wishlist from n/a through 1.0.39.
CVE-2025-24655 impacts the PickPlugins Wishlist and WordPress Wishlist Plugin.