Cross-site Scripting Vulnerability in Anant Addons for Elementor by Anantaddons
CVE-2025-50038

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 June 2025

What is CVE-2025-50038?

Anant Addons for Elementor has a vulnerability where improper neutralization of input during web page generation can lead to stored Cross-site Scripting (XSS). This flaw allows attackers to inject malicious scripts into web pages, potentially impacting users visiting the compromised page. Generating web content that does not adequately sanitize user input exposes sites to various security threats. Affected versions include those prior to 1.2.0.

Affected Version(s)

Anant Addons for Elementor <= 1.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Prissy (Patchstack Alliance)
.