Stored Cross-Site Scripting in Qi Addons For Elementor Plugin for WordPress
CVE-2025-6252

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 June 2025

What is CVE-2025-6252?

The Qi Addons For Elementor plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. This issue allows authenticated attackers, with Contributor access or higher, to exploit multiple parameters. By doing so, they can inject malicious web scripts into pages, which will execute when users access those compromised pages, potentially leading to harmful consequences such as data theft or session hijacking.

Affected Version(s)

Qi Addons For Elementor * <= 1.9.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Craig Smith
.
CVE-2025-6252 : Stored Cross-Site Scripting in Qi Addons For Elementor Plugin for WordPress