plugin

Salesforce Wordpress To Candidate Vulnerabilities

2 known security issues reported for the Salesforce Wordpress To Candidate WordPress plugin. Most recent disclosed Feb 14, 2025.

1 medium

Running Salesforce Wordpress To Candidate on your site? Check whether your installed version is affected.

Scan your site free

WordPress-to-candidate for Salesforce CRM [salesforce-wordpress-to-candidate] <= 1.0.1 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WordPress-to-candidate for Salesforce CRM allows Reflected XSS. This issue affects WordPress-to-candidate for Salesforce CRM: from n/a through 1.0.1.

Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Feb 14, 2025

CVE-2025-23657 on NVD →

WordPress-to-candidate for Salesforce CRM <= 1.0.1 - Reflected Cross-Site Scripting

medium

The WordPress-to-candidate for Salesforce CRM plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...

CVSS:
6.1
Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Jan 16, 2025

CVE-2025-23657 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database