CVE-2025-24565
Published: 14 February 2025
Summary
CVE-2025-24565 is a high-severity Cross-site Scripting (CWE-79) vulnerability. Its CVSS base score is 7.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 32.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-15 (Information Output Filtering).
Deeper analysis
CVE-2025-24565 is an Improper Neutralization of Input During Web Page Generation vulnerability, classified as Reflected Cross-site Scripting (XSS) under CWE-79, in the WP2LEADS WordPress plugin developed by Saleswonder Team: Tobias. The flaw affects all versions of the WP2LEADS plugin from n/a through 3.3.3, allowing malicious input to be reflected without proper neutralization during web page generation.
The vulnerability carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating it is exploitable over the network with low attack complexity by unauthenticated attackers requiring user interaction, such as clicking a malicious link. Exploitation enables script execution in the context of the victim's browser, resulting in low impacts to confidentiality, integrity, and availability, with a changed scope that may affect additional resources.
The Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/wp2leads/vulnerability/wordpress-wp2leads-plugin-3-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve documents this Reflected XSS issue in WP2LEADS version 3.3.3 and related versions. Security practitioners should review this reference for details on available patches and recommended mitigations.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-3773
Vulnerability details
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.3.3.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Reflected XSS vulnerability in public-facing WordPress plugin enables exploitation of the web application (T1190) and direct execution of arbitrary JavaScript in the victim's browser (T1059.007).
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Information Output Filtering directly neutralizes reflected malicious input before rendering in web pages, preventing XSS script execution in victims' browsers.
Information Input Validation rejects or sanitizes untrusted inputs containing XSS payloads before processing in the WP2LEADS plugin.
Flaw Remediation requires timely patching of the specific improper neutralization flaw in WP2LEADS versions through 3.3.3.