Cross-Site Scripting Vulnerability in PhiloPress BP Email Assign Templates
CVE-2025-24631

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
3 February 2025

Summary

PhiloPress BP Email Assign Templates has a vulnerability due to improper neutralization of input during web page generation, allowing for reflected Cross-Site Scripting (XSS) attacks. This vulnerability can potentially allow an attacker to inject malicious scripts into webpages viewed by other users, thereby compromising user data and compromising web application integrity. The affected versions range from n/a through 1.5, highlighting the importance of ensuring that users operate the latest, patched versions to mitigate risks.

Affected Version(s)

BP Email Assign Templates <= 1.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3 (Patchstack Alliance)
.