CVE-2025-59467: XSS
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page.
This plugin is disabled by default.
Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier)
Mitigation: Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59467?
The severity of CVE-2025-59467 is classified as medium due to its potential for privilege escalation.
How do I fix CVE-2025-59467?
To fix CVE-2025-59467, upgrade the UCRM Argentina AFIP invoices Plugin to version 1.2.1 or later.
What impact does CVE-2025-59467 have on users?
CVE-2025-59467 can allow an attacker to execute cross-site scripting attacks if an administrator visits a crafted page.
Is CVE-2025-59467 exploitable in default installations?
CVE-2025-59467 is not exploitable in default installations as the affected plugin is disabled by default.
Who is affected by CVE-2025-59467?
Users of the UCRM Argentina AFIP invoices Plugin version 1.2.0 and earlier are affected by CVE-2025-59467.