CVE-2025-24708

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-dynamics-crm allows Reflected XSS.This issue affects WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through <= 1.1.6.
CVSS

No CVSS.

Configurations

No configuration.

History

01 Apr 2026, 17:18

Type Values Removed Values Added
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/cf7-dynamics-crm/vulnerability/wordpress-wp-dynamics-crm-plugin-1-1-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/cf7-dynamics-crm/vulnerability/wordpress-wp-dynamics-crm-plugin-1-1-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve -
Summary
  • (es) Vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web ('Cross-site Scripting') en CRM Perks WP Dynamics CRM para Contact Form 7, WPForms, Elementor, Formidable y Ninja Forms permite XSS reflejado. Este problema afecta a WP Dynamics CRM para Contact Form 7, WPForms, Elementor, Formidable y Ninja Forms: desde n/a hasta 1.1.6.
Summary (en) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms allows Reflected XSS. This issue affects WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through 1.1.6. (en) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-dynamics-crm allows Reflected XSS.This issue affects WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through <= 1.1.6.
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : unknown

27 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 15:15

Updated : 2026-04-01 17:18


NVD link : CVE-2025-24708

Mitre link : CVE-2025-24708

CVE.ORG link : CVE-2025-24708


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')