First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks allows Reflected XSS. This issue affects CRM Perks: from n/a through 1.1.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CRM Perks | <=1.1.7 | |
CRM Perks | <=1.1.7 |
Update the WordPress CRM Perks plugin to the latest available version (at least 1.1.8).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-39558 is a reflected cross-site scripting (XSS) vulnerability, which can potentially allow attackers to inject malicious scripts into web pages.
To fix CVE-2025-39558, update CRM Perks to a version later than 1.1.7 that addresses the reflected XSS vulnerability.
CVE-2025-39558 affects all versions of CRM Perks from n/a through 1.1.7.
If you cannot update, consider implementing web application firewalls or XSS filtering to help mitigate the impact of CVE-2025-39558.
Yes, CVE-2025-39558 is relatively easy to exploit, as it involves injecting scripts through user input without proper validation.