Unrated severityNVD Advisory· Published Jan 5, 2026· Updated Jan 5, 2026
CVE-2025-59467
CVE-2025-59467
Description
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page.
This plugin is disabled by default.
Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier)
Mitigation: Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.
Affected products
2- Range: <=1.2.0
- Range: <=1.2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.