Stored Cross-Site Scripting Flaw in aThemes Addons for Elementor
CVE-2025-22646

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 March 2025

What is CVE-2025-22646?

The aThemes Addons for Elementor plugin suffers from a stored Cross-Site Scripting (XSS) vulnerability due to improper handling of user input during webpage generation. An attacker can exploit this flaw to inject malicious scripts that may execute in the context of users who view the affected web pages. This can lead to unauthorized access, data theft, or other malicious actions. This issue affects versions of the aThemes Addons for Elementor plugin up to and including 1.0.8.

Affected Version(s)

aThemes Addons for Elementor 0 <= 1.0.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael (Patchstack Alliance)
.