Cross-site Scripting Vulnerability in Hashthemes Easy Elementor Addons
CVE-2025-48295

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 July 2025

What is CVE-2025-48295?

The Easy Elementor Addons plugin by Hashthemes is susceptible to a Cross-site Scripting (XSS) vulnerability, specifically through improper neutralization of input during web page generation. This flaw allows adversaries to inject malicious scripts, which can be executed when users interact with the compromised web pages. All installations of Easy Elementor Addons from its initial release up to version 2.2.5 are affected, posing significant risks to the security of websites employing this plugin. It is crucial for website administrators to apply the latest security updates and follow best practices for input validation to mitigate this issue.

Affected Version(s)

Easy Elementor Addons <= 2.2.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

stealthcopter (Patchstack Alliance)
.
CVE-2025-48295 : Cross-site Scripting Vulnerability in Hashthemes Easy Elementor Addons