Cross-site Scripting Vulnerability in Make Section & Column Clickable For Elementor by Riyadh Ahmed
CVE-2025-63033

5.9MEDIUM

What is CVE-2025-63033?

A Cross-site Scripting (XSS) vulnerability affects the Make Section & Column Clickable For Elementor plugin developed by Riyadh Ahmed. This flaw allows for the injection of malicious scripts into web pages viewed by unsuspecting users. The vulnerability exists in versions n/a through 2.3, enabling attackers to exploit the input mechanisms used in web page generation, leading to stored XSS attacks. Users of the affected plugin should implement necessary security measures and consider updating to a patched version to mitigate this risk.

Affected Version(s)

Make Section & Column Clickable For Elementor 0 <= 2.4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mdr | Patchstack Bug Bounty Program
.