Cross-site Scripting Vulnerability in HT Mega – Absolute Addons for WPBakery Page Builder
CVE-2025-53463

6.5MEDIUM

What is CVE-2025-53463?

A Cross-site Scripting (XSS) vulnerability has been identified in HT Mega – Absolute Addons for WPBakery Page Builder. This flaw occurs due to improper neutralization of user inputs during web page generation, allowing attackers to execute arbitrary scripts in the context of the user's browser. This vulnerability affects various versions of the plugin up to 1.0.9, potentially compromising the security of affected websites. Proper input sanitization and validation measures are critical to prevent exploitation of this vulnerability.

Affected Version(s)

HT Mega – Absolute Addons for WPBakery Page Builder <= 1.0.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.
CVE-2025-53463 : Cross-site Scripting Vulnerability in HT Mega – Absolute Addons for WPBakery Page Builder