Reflected XSS Vulnerability in Multiple WordPress Plugins by CRM Perks
CVE-2025-24708
7.1HIGH
Key Information:
- Vendor
- Crm Perks
- Status
- WP Dynamics Crm For Contact Form 7, WPforms, Elementor, Formidable And Ninja Forms
- Vendor
- CVE Published:
- 27 January 2025
Summary
A reflected XSS vulnerability exists in the CRM Perks WP Dynamics CRM plugin for several popular WordPress form plugins, including Contact Form 7, WPForms, Elementor, Formidable, and Ninja Forms. This vulnerability allows attackers to inject malicious scripts into web pages, which can be executed in the context of a user's browser. Exploitation may lead to data theft, session hijacking, and other malicious activities, putting users at risk if they interact with compromised forms or links.
Affected Version(s)
WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.6
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdi Pranata (Patchstack Alliance)