First published: Mon Jan 27 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms allows Reflected XSS. This issue affects WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through 1.1.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WP Dynamics CRM | <=1.1.6 | |
WPForms | <=1.1.6 | |
Elementor | <=1.1.6 | |
Formidable Forms by Strategy11 | <=1.1.6 | |
Ninja Forms | <=1.1.6 |
Update the WordPress WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin to the latest available version (at least 1.1.7).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24708 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-24708, update the affected plugins to their latest versions, ensuring that they are beyond version 1.1.6.
CVE-2025-24708 affects the WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable, and Ninja Forms plugins up to version 1.1.6.
CVE-2025-24708 enables reflected cross-site scripting (XSS) attacks, which can lead to unauthorized access or data exposure.
Yes, CVE-2025-24708 is considered critical because it allows attackers to execute malicious scripts in the context of a victim's browser session.