Reflected Cross-Site Scripting in CreativeMindsSolutions Email Registration Plugin
CVE-2025-24694

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
3 March 2025

Summary

A reflected cross-site scripting vulnerability exists in the CM Email Registration Blacklist and Whitelist plugin developed by CreativeMindsSolutions. This flaw arises from improper neutralization of user input during web page generation. Attackers can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, leading to potential data theft, session hijacking, or other malicious actions. The affected versions extend from an undetermined point through 1.5.5, necessitating prompt awareness and mitigation by users.

Affected Version(s)

CM Email Registration Blacklist and Whitelist <= 1.5.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis (Patchstack Alliance)
.