CVE-2025-24598
📛 CVE Title
WordPress WP Mailster plugin <= 1.8.17.0 - Reflected Cross Site Scripting (XSS) vulnerability
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.This issue affects WP Mailster: from n/a through <= 1.8.17.0.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Patchstack
- CVSS severity
- HIGH
- CVSS score
- 7.1 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L- Effective score
- 7.1 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-79 - Reserved
- 2025-01-23
- Published
- 2025-02-04 15:21 UTC
- Last updated
- 2026-05-12 01:30 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/24xxx/CVE-2025-24598.json
- Linked Threat
- CVE-2025-24598 — WP Mailster <= 1.8.17.0 - Reflected Cross-Site Scripting
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2025-02-04 15:15:23 UTC
- NVD last modified
- 2026-06-17 08:59:17 UTC
- NVD CVSS v3.1
- 7.1 / 10 HIGH source: audit@patchstack.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 3.7 / 10
- EPSS score
- 0.0025 (probability of exploitation in next 30 days)
- EPSS percentile
- 16.30% vs all CVEs — higher = more likely to be exploited, as of 2026-07-10
NVD / KEV / EPSS data refreshed 2026-07-11 12:34 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2025-3802 - Assigner
- Patchstack
- Published
- Feb 4, 2025, 2:21:14 PM
- Updated
- May 11, 2026, 11:30:24 PM
- EUVD base score (CVSS 3.1)
-
7.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L - EUVD-reported EPSS
- 0.1500
- Vendors
- brandtoss
- Products
-
WP Mailster (n/a ≤1.8.17.0)WP Mailster (0 ≤1.8.17.0)
- Aliases
-
GHSA-q5rj-7wqp-rf58
ENISA description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.This issue affects WP Mailster: from n/a through <= 1.8.17.0.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| brandtoss | WP Mailster |
0 (affected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:wpmailster:wp_mailster:*:*:*:*:*:wordpress:*:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
MITRE references (1) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- http://cwe.mitre.org/data/definitions/79.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2025-24598 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-3802 rapid7:euvd.enisa.europa.eu
- https://www.cve.org/CVERecord?id=CVE-2025-24598 rapid7:www.cve.org
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5b4db6bb-af81-496c-bd23-b777fc16c3e4?source=api-prod rapid7:www.wordfence.com
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
Indicators (3)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| domain |
xss.this
|
no local data | 2026-05-18 21:19 UTC |
| ipv4 |
1.8.17.0
|
no local data | 2026-05-18 21:19 UTC |
| cve |
CVE-2025-24598
|
no local data | 2026-06-06 14:07 UTC |
Remediations (21)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
Wordfence remediation: WP MailsterWordfence
Update to version 1.8.18.0, or a newer patched version
2026-06-06 14:07 UTC -
web:cybersecuritynews.com
Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.
2026-05-22 12:37 UTC -
web:source.android.com
Android partners are encouraged to fix all issues in this bulletin and use the latest security patch level. Devices that use the 2025 -09-01 security patch level must include all issues associated with that security patch level, as well as fixes for all issues reported in previous security bulletins.
2026-05-22 12:37 UTC -
web:krebsonsecurity.com
Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known "zero-day" or actively exploited ...
2026-05-22 12:37 UTC -
web:learn.microsoft.com
Microsoft December 2025 Security Updates This release consists of the following 57 Microsoft CVEs : Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations ? Windows PowerShell CVE - 2025 -54100 Windows Projected File System…
2026-05-22 12:37 UTC -
web:blog.qualys.com
Microsoft Patch Tuesday for September 2025 In this month's Patch Tuesday, the September 2025 edition, Microsoft addressed 86 vulnerabilities. The updates include nine critical and 72 important severity vulnerabilities. In this month's updates, Microsoft has addressed two zero-day vulnerabilities that are being publicly disclosed.
2026-05-22 12:37 UTC -
web:www.cisecurity.org
<p>Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...
2026-05-22 12:37 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-22 12:37 UTC -
web:www.elevenforum.com
November 2025 Security Updates This release consists of the following 63 Microsoft CVEs : Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations ? Nuance PowerScribe CVE - 2025 -30398 Microsoft Configuration Manager CVE - 2025 -47179 Microsoft Office Excel CVE - 2025 -59240 SQL...
2026-05-22 12:37 UTC -
web:www.oracle.com
This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 12:37 UTC -
web:www.sentinelone.com
CVE - 2025 -46598 is a denial of service vulnerability in Bitcoin Core through 29.0. Learn about its impact, affected versions, and mitigation methods.
2026-05-22 12:37 UTC -
web:www.forbes.com
Microsoft has confirmed an emergency security update as CISA warns that two new Defender zero-days are being exploited by attackers.
2026-05-22 02:44 UTC -
web:dailysecurityreview.com
CISA adds five actively exploited vulnerabilities, including CVE - 2025 -61884, to its KEV catalog. Patch now to reduce exposure and security risk.
2026-05-22 02:44 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-05-22 02:44 UTC -
web:www.cvefind.com
CVE Find is a real-time vulnerability database indexing 351 731 security flaws ( CVE ) from MITRE, NVD, CISA KEV, CWE and CAPEC. 1311 new CVEs were published in the last 7 days. Data aggregated from: MITRE Corporation ( CVE , CWE, CAPEC), National Vulnerability Database - NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
2026-05-22 02:44 UTC -
web:www.romhacking.net
Add temporary header() Patch file: Apply patch Original ROM: Modified ROM: Patch type: IPS BPS PPF UPS APS RUP Create patch Settings Rom Patcher JS v2.9 by Marc Robledo See on GitHub Donate Language English Français Deutsch Italiano Español Nederlands Svenska Català Valencià Português Brasileiro Russian 日本語 中文(简体) 中文 ...
2026-05-22 02:44 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-05-22 02:44 UTC -
web:na.finalfantasyxiv.com
Out April 28, 2026 New Story Main Scenario Quests Trail to the Heavens - Part 1 PATCH 7.5 Returned from the levin-wracked lands of the Ninth, the Warrior of Light and their companions resume investigations into the key. Yet as they begin to unravel its mysteries, an ally's unsettling message threatens to draw their attention elsewhere...
2026-05-22 02:44 UTC -
web:nvd.nist.gov
Please make use of the interactive search interfaces to find information in the database!
2026-05-22 02:44 UTC -
web:patch.com
The best breaking news, stories, and events from the Patch network of local news sites
2026-05-22 02:44 UTC -
web:www.fixferreterias.com
FIX FERRETERÍAS Acerca de nosotros Ubica tu tienda Catálogo Grupo Truper SOPORTE AL CLIENTE Facturación Cotizaciones Preguntas Frecuentes Mis pedidos POLÍTICAS Ventas Devoluciones Garantías Precios Aviso de privacidad
2026-05-22 02:44 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2025-24598.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-24598",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-02-04T15:09:32.632160Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T23:30:24.372Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "wp-mailster",
"product": "WP Mailster",
"vendor": "brandtoss",
"versions": [
{
"changes": [
{
"at": "1.8.18.0",
"status": "unaffected"
}
],
"lessThanOrEqual": "1.8.17.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "LVT-tholv2k | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-04-01T16:34:03.331Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.<p>This issue affects WP Mailster: from n/a through <= 1.8.17.0.</p>"
}
],
"value": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.This issue affects WP Mailster: from n/a through <= 1.8.17.0."
}
],
"impacts": [
{
"capecId": "CAPEC-591",
"descriptions": [
{
"lang": "en",
"value": "Reflected XSS"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-28T16:11:29.393Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/Wordpress/Plugin/wp-mailster/vulnerability/wordpress-wp-mailster-plugin-1-8-17-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"title": "WordPress WP Mailster plugin <= 1.8.17.0 - Reflected Cross Site Scripting (XSS) vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2025-24598",
"datePublished": "2025-02-04T14:21:14.713Z",
"dateReserved": "2025-01-23T14:50:57.839Z",
"dateUpdated": "2026-05-11T23:30:24.372Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}