Stored XSS Vulnerability in Grand Restaurant Theme Elements for Elementor by ThemeGoods
CVE-2025-63026
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 January 2026
What is CVE-2025-63026?
A Stored Cross-site Scripting (XSS) vulnerability exists within the Grand Restaurant Theme Elements for Elementor, developed by ThemeGoods. This flaw allows malicious users to inject harmful scripts into web pages viewed by other users. The vulnerability impacts versions from n/a up to 2.1.1, potentially leading to unauthorized access and exploitation of user data. It's crucial for website owners utilizing this theme to apply necessary updates to mitigate risks associated with this susceptibility.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Grand Restaurant Theme Elements for Elementor 0 <= 2.1.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved