Cross-site Scripting Vulnerability in Make Column Clickable Elementor by Fernando Acosta
CVE-2025-59592
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2025
What is CVE-2025-59592?
A security flaw has been identified in the Make Column Clickable Elementor plugin by Fernando Acosta, which allows for improper neutralization of user input during web page generation. This flaw could enable attackers to execute arbitrary JavaScript in the context of a user's session, potentially leading to unauthorized actions or data exposure. It is crucial for users of the affected versions (up to 1.6.0) to evaluate their security posture and apply necessary updates to mitigate this vulnerability.
Affected Version(s)
Make Column Clickable Elementor <= 1.6.0