Cross-site Scripting Vulnerability in Easy Elementor Addons by Hashthemes
CVE-2025-54704

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 August 2025

What is CVE-2025-54704?

The Easy Elementor Addons plugin by Hashthemes is vulnerable to a cross-site scripting (XSS) flaw. This vulnerability stems from improper neutralization of user input during web page generation, potentially allowing an attacker to execute arbitrary JavaScript in the context of the user's browser. If exploited, this could lead to unauthorized actions on behalf of the user, compromising sensitive information and site integrity. The vulnerability affects versions from n/a through 2.2.6, making it imperative for users to review their settings and update to the latest version.

Affected Version(s)

Easy Elementor Addons <= 2.2.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abu Hurayra (Patchstack Alliance)
.
CVE-2025-54704 : Cross-site Scripting Vulnerability in Easy Elementor Addons by Hashthemes