Stored Cross-Site Scripting Vulnerability in Master Addons for WordPress
CVE-2025-0433
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 March 2025
What is CVE-2025-0433?
The Master Addons β Elementor Addons for WordPress contains a vulnerability that allows authenticated attackers with Contributor-level access or higher to exploit the 'id' parameter. Due to inadequate input sanitization and output escaping, these attackers can inject arbitrary scripts into web pages. When users visit the compromised pages, the injected scripts execute, potentially leading to unauthorized control or data theft. It is crucial for users of versions up to 2.0.7.1 to take immediate action to secure their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Master Addons β Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations * <= 2.0.7.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved