Cross-site Scripting Vulnerability in Make Section & Column Clickable For Elementor by Riyadh Ahmed
CVE-2025-63033
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-63033?
A Cross-site Scripting (XSS) vulnerability affects the Make Section & Column Clickable For Elementor plugin developed by Riyadh Ahmed. This flaw allows for the injection of malicious scripts into web pages viewed by unsuspecting users. The vulnerability exists in versions n/a through 2.3, enabling attackers to exploit the input mechanisms used in web page generation, leading to stored XSS attacks. Users of the affected plugin should implement necessary security measures and consider updating to a patched version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Make Section & Column Clickable For Elementor <= n/a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved