Stored Cross-Site Scripting in Qi Addons For Elementor Plugin for WordPress
CVE-2025-6252
5.4MEDIUM
What is CVE-2025-6252?
The Qi Addons For Elementor plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. This issue allows authenticated attackers, with Contributor access or higher, to exploit multiple parameters. By doing so, they can inject malicious web scripts into pages, which will execute when users access those compromised pages, potentially leading to harmful consequences such as data theft or session hijacking.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Qi Addons For Elementor * <= 1.9.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Craig Smith