CVE-2025-24699: WordPress WP Coder Plugin <= 3.6 - CSRF to Cross Site Scripting (XSS) vulnerability
Published Feb 14, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company WP Coder wp-coder allows Cross-Site Scripting (XSS).This issue affects WP Coder: from n/a through <= 3.6.
Affected Software
1 affected component
Wow-Company WP Coder<=3.6
Remediation
Information
Update the WordPress WP Coder wordpress plugin to the latest available version (at least 3.6.1).
Event History
Feb 14, 2025
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24699?
CVE-2025-24699 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2025-24699?
To fix CVE-2025-24699, update the WP Coder plugin to version 3.6 or higher.
3
What causes CVE-2025-24699?
CVE-2025-24699 is caused by a Cross-Site Request Forgery (CSRF) vulnerability that allows for Cross-Site Scripting (XSS).
4
Which versions of WP Coder are affected by CVE-2025-24699?
CVE-2025-24699 affects all versions of WP Coder up to and including version 3.6.
5
Can CVE-2025-24699 be exploited remotely?
Yes, CVE-2025-24699 can be exploited remotely, potentially allowing attackers to execute XSS attacks.