Stored Cross-Site Scripting in Sina Extension for Elementor by Sina
CVE-2025-1517
6.4MEDIUM
Key Information:
- Vendor
- Shaonsina
- Status
- Sina Extension For Elementor (slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates)
- Vendor
- CVE Published:
- 26 February 2025
Summary
The Sina Extension for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) vulnerabilities due to inadequate sanitization and escaping of user-inputted data in key functionalities such as Fancy Text, Countdown Widget, and Login Form shortcodes. This vulnerability allows authenticated attackers with contributor-level permissions or higher to inject malicious scripts into pages, which will execute in the browsers of users accessing the affected pages, potentially compromising sensitive information.
Affected Version(s)
Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) * <= 3.6.0
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
D.Sim