Stored Cross-site Scripting Vulnerability in Better WishList API by rickonline_nl
CVE-2025-24641
7.1HIGH
What is CVE-2025-24641?
The Better WishList API plugin by rickonline_nl contains a vulnerability due to improper neutralization of input during web page generation, which can lead to Stored Cross-site Scripting (XSS). This vulnerability could allow attackers to inject malicious scripts into pages viewed by users, compromising data integrity and exposing sensitive information. The issue affects all versions of the Better WishList API up to and including version 1.1.3.
Affected Version(s)
Better WishList API <= 1.1.3