CVE-2025-24289
HIGHUCRM Client Signup Plugin <1.3.4 - CSRF/XSS
Title source: llmDescription
A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default.
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
5.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-352
Status
draft
Timeline
Published
Jun 29, 2025
Tracked Since
Feb 18, 2026