Medium 6.4
2025-07-22< 2.8.0
CRM and Lead Management by vcita <= 2.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter
Minimum safe version
2.8.0
Update to 2.8.0 or later to address 5 fixable vulnerabilities
CRM and Lead Management by vcita <= 2.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter
CVE-2024-13702
CVE-2024-13703
WordPress CRM and Lead Management by vcita Plugin <= 2.6.2 is vulnerable to Cross Site Scripting (XSS)
WordPress CRM and Lead Management by vcita Plugin <= 2.6.2 is vulnerable to Cross Site Scripting (XSS)