Stored XSS Vulnerability in Formafzar Plugin by Instaform
CVE-2025-22524
6.5MEDIUM
What is CVE-2025-22524?
The Formafzar plugin developed by Instaform is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs due to improper neutralization of user input when generating web pages, allowing malicious scripts to be stored and executed within the application. This could allow attackers to execute arbitrary code in the users' sessions, potentially compromising sensitive data and user interactions. The vulnerability affects versions from n/a through 2.0. To safeguard against exploitation, it is crucial for users to keep their plugins updated and implement proper security measures.
Affected Version(s)
فرم ساز فرم افزار <= 2.0