Stored Cross-Site Scripting Flaw in aThemes Addons for Elementor
CVE-2025-22646
6.5MEDIUM
What is CVE-2025-22646?
The aThemes Addons for Elementor plugin suffers from a stored Cross-Site Scripting (XSS) vulnerability due to improper handling of user input during webpage generation. An attacker can exploit this flaw to inject malicious scripts that may execute in the context of users who view the affected web pages. This can lead to unauthorized access, data theft, or other malicious actions. This issue affects versions of the aThemes Addons for Elementor plugin up to and including 1.0.8.
Affected Version(s)
aThemes Addons for Elementor 0 <= 1.0.8