Stored Cross-Site Scripting in Qi Addons For Elementor Plugin for WordPress
CVE-2025-6252
6.4MEDIUM
What is CVE-2025-6252?
The Qi Addons For Elementor plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. This issue allows authenticated attackers, with Contributor access or higher, to exploit multiple parameters. By doing so, they can inject malicious web scripts into pages, which will execute when users access those compromised pages, potentially leading to harmful consequences such as data theft or session hijacking.
Affected Version(s)
Qi Addons For Elementor * <= 1.9.1