Cross-Site Scripting Vulnerability in Alpha Price Table Plugin by Ali
CVE-2025-22500

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 January 2025

What is CVE-2025-22500?

The Alpha Price Table For Elementor plugin from Ali contains a vulnerability that allows for Cross-site Scripting (XSS) attacks through improper neutralization of input during web page generation. This can potentially allow attackers to execute arbitrary JavaScript in the context of the user's browser, compromising user data and leading to further exploitation. This vulnerability affects versions from unspecified prior versions to 1.0.8.

Affected Version(s)

Alpha Price Table For Elementor 0 <= 1.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.