CVE-2025-24619
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Apr 17, 2025
CWE ID 79
Summary
CVE-2025-24619 is a Cross-site Scripting (XSS) vulnerability affecting the WP Log Action plugin, version n/a through 0.51. Malicious scripts can be injected into web pages generated by this plugin due to improper neutralization of user inputs. This issue poses a significant risk, as attackers can steal user data, manipulate web sessions, or execute malicious code on vulnerable systems. Users are advised to update to the latest version or consider disabling the plugin as a temporary measure while a patch is applied.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.