Stored XSS Vulnerability in Vertex Addons for Elementor by Webilia Inc.
CVE-2025-26769

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 February 2025

What is CVE-2025-26769?

A Stored Cross-site Scripting (XSS) vulnerability exists in the Vertex Addons for Elementor plugin provided by Webilia Inc. This issue enables attackers to inject malicious scripts that are stored on the server and later executed in the browsers of users accessing affected areas of the application. The vulnerability affects all versions up to and including 1.2.0, allowing unauthorized access to sensitive data and interaction with users unknowingly. It underscores the importance of sanitation and validation in web application development.

Affected Version(s)

Vertex Addons for Elementor 0 <= 1.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Webula (Patchstack Alliance)
.