CVE-2025-39542
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 17, 2025
CWE ID 266
Summary
CVE-2025-39542 is a Privilege Escalation vulnerability affecting the Xelion Webchat application, version n/a through 9.1.0. The flaw stems from an Incorrect Privilege Assignment issue, which grants unauthorized access to higher-level functions within the system. An attacker who successfully exploits this vulnerability can escalate their privileges and potentially gain control over the affected system, leading to serious security consequences. Users are urged to update their Xelion Webchat installation as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Xelion Webchat Plugin
Affected Vendors
- WordPress