Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - CRM for Contact form CF7 & WooCommerce wpcrm allows Reflected XSS.This issue affects WPCRM - CRM for Contact form CF7 & WooCommerce: from n/a through <= 3.2.0.
Published: 2025-06-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WPCRM – CRM for Contact form CF7 & WooCommerce plugin includes a path where user‑supplied input is not properly neutralized before being embedded in an HTML response. An attacker can supply crafted data through a form field or a manipulated URL, causing the plugin to echo the malicious payload back to the browser. This allows execution of JavaScript in the context of any visitor, potentially enabling credential theft, site defacement, or redirect attacks. The flaw is classified as CWE‑79, reflecting its nature as a reflected XSS vulnerability that impacts confidentiality, integrity, and availability of the affected WordPress site.

Affected Systems

Affected installations are all WordPress sites that have the WPCRM plugin version 3.2.0 or earlier – that is, the vulnerability exists in every build from the earliest release up through 3.2.0. The vendor, mojoomla, lists this coverage and no higher‑version range is fixed, so any site using 3.2.0 remains at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderately high risk environment, but the EPSS value of less than 1% suggests that large‑scale exploitation has not yet been observed. Because the vulnerability is triggered by rendering user input into a page, the exploitation path requires that an attacker convince or trick a user to submit crafted data or visit a malicious URL. No privilege escalation or external system compromise is necessary – the attack successfully impacts any visitor to the vulnerable page. The vulnerability is not currently listed in CISA’s KEV catalog, but its severity warrants careful monitoring and mitigation.

Generated by OpenCVE AI on May 2, 2026 at 08:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPCRM to a patched version (e.g., 3.3.0 or later) supplied by mojoomla as soon as it becomes available
  • If upgrading is not possible, disable or uninstall the plugin and replace it with an alternative, well‑maintained CRM solution
  • Implement server‑side input validation and sanitization for all form fields, or install a security plugin that blocks reflected XSS, and consider adding a Content Security Policy to restrict script execution until a vendor fix is applied

Generated by OpenCVE AI on May 2, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19261 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - CRM for Contact form CF7 & WooCommerce allows Reflected XSS. This issue affects WPCRM - CRM for Contact form CF7 & WooCommerce: from n/a through 3.2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - CRM for Contact form CF7 & WooCommerce allows Reflected XSS. This issue affects WPCRM - CRM for Contact form CF7 & WooCommerce: from n/a through 3.2.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - CRM for Contact form CF7 & WooCommerce wpcrm allows Reflected XSS.This issue affects WPCRM - CRM for Contact form CF7 & WooCommerce: from n/a through <= 3.2.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 27 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 12:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - CRM for Contact form CF7 & WooCommerce allows Reflected XSS. This issue affects WPCRM - CRM for Contact form CF7 & WooCommerce: from n/a through 3.2.0.
Title WordPress WPCRM - CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:34.590Z

Reserved: 2025-01-23T14:53:25.027Z

Link: CVE-2025-24774

cve-icon Vulnrichment

Updated: 2025-06-27T12:42:46.683Z

cve-icon NVD

Status : Deferred

Published: 2025-06-27T12:15:31.200

Modified: 2026-06-17T08:59:35.160

Link: CVE-2025-24774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T08:30:26Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')