Stored Cross-Site Scripting Vulnerability in Master Addons for WordPress
CVE-2025-0433
5.4MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 4 March 2025
Summary
The Master Addons – Elementor Addons for WordPress contains a vulnerability that allows authenticated attackers with Contributor-level access or higher to exploit the 'id' parameter. Due to inadequate input sanitization and output escaping, these attackers can inject arbitrary scripts into web pages. When users visit the compromised pages, the injected scripts execute, potentially leading to unauthorized control or data theft. It is crucial for users of versions up to 2.0.7.1 to take immediate action to secure their installations.
Affected Version(s)
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations * <= 2.0.7.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Matthew Rollings