Reflected Cross-Site Scripting in CreativeMindsSolutions Email Registration Plugin
CVE-2025-24694
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 March 2025
What is CVE-2025-24694?
A reflected cross-site scripting vulnerability exists in the CM Email Registration Blacklist and Whitelist plugin developed by CreativeMindsSolutions. This flaw arises from improper neutralization of user input during web page generation. Attackers can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, leading to potential data theft, session hijacking, or other malicious actions. The affected versions extend from an undetermined point through 1.5.5, necessitating prompt awareness and mitigation by users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CM Email Registration Blacklist and Whitelist <= 1.5.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved