Cross-Site Scripting Vulnerability in Exclusive Addons Elementor by Tim Strifler
CVE-2025-48244

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 May 2025

What is CVE-2025-48244?

The vulnerability in Exclusive Addons Elementor, developed by Tim Strifler, pertains to improper handling of user input, which can lead to stored cross-site scripting (XSS) attacks. This issue enables malicious actors to inject scripts into web pages that are then rendered in the browsers of users who view those pages. Such vulnerabilities pose significant risks as they can expose sensitive user data, compromise session information, and lead to further exploitation of the website. Users utilizing versions of Exclusive Addons Elementor up to 2.7.9 should consider immediate updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Exclusive Addons Elementor <= 2.7.9

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.
The Cyber Security Vulnerability Database.