Stored XSS Vulnerability in Grand Restaurant Theme Elements for Elementor by ThemeGoods
CVE-2025-63026
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 January 2026
What is CVE-2025-63026?
A Stored Cross-site Scripting (XSS) vulnerability exists within the Grand Restaurant Theme Elements for Elementor, developed by ThemeGoods. This flaw allows malicious users to inject harmful scripts into web pages viewed by other users. The vulnerability impacts versions from n/a up to 2.1.1, potentially leading to unauthorized access and exploitation of user data. It's crucial for website owners utilizing this theme to apply necessary updates to mitigate risks associated with this susceptibility.
Affected Version(s)
Grand Restaurant Theme Elements for Elementor 0 <= 2.1.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program