Reflected XSS Vulnerability in Multiple WordPress Plugins by CRM Perks
CVE-2025-24708
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 January 2025
What is CVE-2025-24708?
A reflected XSS vulnerability exists in the CRM Perks WP Dynamics CRM plugin for several popular WordPress form plugins, including Contact Form 7, WPForms, Elementor, Formidable, and Ninja Forms. This vulnerability allows attackers to inject malicious scripts into web pages, which can be executed in the context of a user's browser. Exploitation may lead to data theft, session hijacking, and other malicious activities, putting users at risk if they interact with compromised forms or links.
Affected Version(s)
WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.6