First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing allows Reflected XSS. This issue affects Classified Listing: from n/a through 4.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
RadiusTheme Classified Listing | <=4.0.1 | |
WordPress Classified Listing | <=4.0.1 |
Update the WordPress Classified Listing wordpress plugin to the latest available version (at least 4.0.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24745 is classified as a reflected cross-site scripting (XSS) vulnerability.
To fix CVE-2025-24745, update the RadiusTheme Classified Listing plugin to version 4.0.2 or later.
CVE-2025-24745 affects users of the RadiusTheme and WordPress Classified Listing plugins up to version 4.0.1.
CVE-2025-24745 facilitates reflected cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
CVE-2025-24745 was reported as a vulnerability affecting versions of Classified Listing up to 4.0.1.