PT-2025-27378 · Unknown · Ucrm Client Signup Plugin

Published

2025-06-29

·

Updated

2025-06-30

·

CVE-2025-24289

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: UCRM Client Signup Plugin versions 1.3.4 and earlier
Description: A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) issue could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default.
Recommendations: For UCRM Client Signup Plugin versions 1.3.4 and earlier, consider disabling the plugin until a patch is available to prevent potential exploitation.

Fix

LPE

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-24289

Affected Products

Ucrm Client Signup Plugin