Reflected XSS Vulnerability in Multiple WordPress Plugins by CRM Perks
CVE-2025-24708

7.1HIGH

Key Information:

Vendor
Crm Perks
Status
WP Dynamics Crm For Contact Form 7, WPforms, Elementor, Formidable And Ninja Forms
Vendor
CVE Published:
27 January 2025

Summary

A reflected XSS vulnerability exists in the CRM Perks WP Dynamics CRM plugin for several popular WordPress form plugins, including Contact Form 7, WPForms, Elementor, Formidable, and Ninja Forms. This vulnerability allows attackers to inject malicious scripts into web pages, which can be executed in the context of a user's browser. Exploitation may lead to data theft, session hijacking, and other malicious activities, putting users at risk if they interact with compromised forms or links.

Affected Version(s)

WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.