Stored Cross-Site Scripting Vulnerability in aThemes Addons for Elementor Plugin
CVE-2025-12837
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 November 2025
What is CVE-2025-12837?
The aThemes Addons for Elementor plugin for WordPress has a vulnerability that allows authenticated users with contributor-level permissions and above to execute arbitrary web scripts via the 'Call To Action' widget. This security concern arises from inadequate input sanitization and output escaping of user-supplied values. When these scripts are injected into pages, they will run whenever a user accesses the compromised content, posing significant risks to website integrity and user safety.
Affected Version(s)
aThemes Addons for Elementor * <= 1.1.5