Stored Cross-Site Scripting in Sina Extension for Elementor by Sina
CVE-2025-1517

6.4MEDIUM

Key Information:

Vendor
Shaonsina
Status
Sina Extension For Elementor (slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates)
Vendor
CVE Published:
26 February 2025

Summary

The Sina Extension for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) vulnerabilities due to inadequate sanitization and escaping of user-inputted data in key functionalities such as Fancy Text, Countdown Widget, and Login Form shortcodes. This vulnerability allows authenticated attackers with contributor-level permissions or higher to inject malicious scripts into pages, which will execute in the browsers of users accessing the affected pages, potentially compromising sensitive information.

Affected Version(s)

Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) * <= 3.6.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D.Sim
.