Reflected XSS Vulnerability in Multiple WordPress Plugins by CRM Perks
CVE-2025-24708
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 January 2025
What is CVE-2025-24708?
A reflected XSS vulnerability exists in the CRM Perks WP Dynamics CRM plugin for several popular WordPress form plugins, including Contact Form 7, WPForms, Elementor, Formidable, and Ninja Forms. This vulnerability allows attackers to inject malicious scripts into web pages, which can be executed in the context of a user's browser. Exploitation may lead to data theft, session hijacking, and other malicious activities, putting users at risk if they interact with compromised forms or links.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved