CVE-2025-63048: WordPress ListingPro Lead Form plugin <= 1.0.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro Lead Form listingpro-lead-form allows DOM-Based XSS.This issue affects ListingPro Lead Form: from n/a through <= 1.0.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro Lead Form listingpro-lead-form allows DOM-Based XSS.This issue affects ListingPro Lead Form: from n/a through <= 1.0.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63048?
CVE-2025-63048 is classified as a medium-severity vulnerability due to its potential impact on user data security.
How do I fix CVE-2025-63048?
To fix CVE-2025-63048, update the ListingPro Lead Form to version 1.0.3 or later to address the cross-site scripting issue.
What types of attacks can be executed using CVE-2025-63048?
CVE-2025-63048 allows for DOM-Based Cross-site Scripting (XSS) attacks, which can lead to unauthorized actions on behalf of users.
Which versions of the ListingPro Lead Form are affected by CVE-2025-63048?
CVE-2025-63048 impacts ListingPro Lead Form versions up to and including 1.0.2.
Is it possible for a user to be exploited through CVE-2025-63048?
Yes, users can be exploited through CVE-2025-63048 if they visit a compromised page that leverages the XSS vulnerability.