Stored Cross-Site Scripting Vulnerability in Master Addons for WordPress
CVE-2025-0433
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 March 2025
What is CVE-2025-0433?
The Master Addons – Elementor Addons for WordPress contains a vulnerability that allows authenticated attackers with Contributor-level access or higher to exploit the 'id' parameter. Due to inadequate input sanitization and output escaping, these attackers can inject arbitrary scripts into web pages. When users visit the compromised pages, the injected scripts execute, potentially leading to unauthorized control or data theft. It is crucial for users of versions up to 2.0.7.1 to take immediate action to secure their installations.
Affected Version(s)
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations * <= 2.0.7.1