Stored Cross-Site Scripting in Sina Extension for Elementor by Sina
CVE-2025-1517
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 February 2025
What is CVE-2025-1517?
The Sina Extension for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) vulnerabilities due to inadequate sanitization and escaping of user-inputted data in key functionalities such as Fancy Text, Countdown Widget, and Login Form shortcodes. This vulnerability allows authenticated attackers with contributor-level permissions or higher to inject malicious scripts into pages, which will execute in the browsers of users accessing the affected pages, potentially compromising sensitive information.
Affected Version(s)
Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) * <= 3.6.0