CVE-2025-24708: WordPress WP Dynamics CRM plugin <= 1.1.6 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-dynamics-crm allows Reflected XSS.This issue affects WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through <= 1.1.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24708?
CVE-2025-24708 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-24708?
To fix CVE-2025-24708, update the affected plugins to their latest versions, ensuring that they are beyond version 1.1.6.
What software is affected by CVE-2025-24708?
CVE-2025-24708 affects the WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable, and Ninja Forms plugins up to version 1.1.6.
What kind of attack does CVE-2025-24708 enable?
CVE-2025-24708 enables reflected cross-site scripting (XSS) attacks, which can lead to unauthorized access or data exposure.
Is CVE-2025-24708 a critical vulnerability?
Yes, CVE-2025-24708 is considered critical because it allows attackers to execute malicious scripts in the context of a victim's browser session.