First published: Mon Mar 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in WPShop.ru CallPhone'r allows Stored XSS. This issue affects CallPhone'r: from n/a through 1.1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPShop.ru CallPhone'r | <=1.1.1 | |
WPShop.ru CallPhone'r | <=1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30550 is classified as a high severity vulnerability due to the potential for cross-site request forgery leading to stored XSS attacks.
To fix CVE-2025-30550, update the CallPhone'r plugin to version 1.1.2 or later.
CVE-2025-30550 affects CallPhone'r versions up to and including 1.1.1.
CVE-2025-30550 can facilitate cross-site request forgery (CSRF) attacks that result in stored XSS vulnerabilities.
CVE-2025-30550 is specific to the WPShop.ru and WordPress implementations of the CallPhone'r plugin.