CVE-2025-32501: WordPress RentSyst plugin <= 2.0.92 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability
Published Apr 9, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in dimafreund RentSyst allows Stored XSS.This issue affects RentSyst: from n/a through 2.0.92.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in dimafreund Rentsyst rentsyst allows Stored XSS.This issue affects Rentsyst: from n/a through <= 2.0.92.
— MITRE
Affected Software
1 affected component
dimafreund RentSyst (WordPress plugin)<=2.0.92
Remediation
Information
Update to 2.0.93 or a higher version.
Event History
Apr 9, 2025
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-32501?
CVE-2025-32501 is classified as a high-severity cross-site request forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-32501?
To fix CVE-2025-32501, update RentSyst to version 2.0.73 or later.
3
Which versions of RentSyst are affected by CVE-2025-32501?
CVE-2025-32501 affects RentSyst versions up to and including 2.0.72.
4
Is WordPress affected by CVE-2025-32501?
Yes, the WordPress RentSyst plugin versions up to and including 2.0.72 are also affected by CVE-2025-32501.
5
What kind of attack is possible due to CVE-2025-32501?
CVE-2025-32501 allows for stored Cross-Site Scripting (XSS) attacks through cross-site request forgery.