Cross-site Scripting Vulnerability in Make Section & Column Clickable For Elementor by Riyadh Ahmed
CVE-2025-63033
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-63033?
A Cross-site Scripting (XSS) vulnerability affects the Make Section & Column Clickable For Elementor plugin developed by Riyadh Ahmed. This flaw allows for the injection of malicious scripts into web pages viewed by unsuspecting users. The vulnerability exists in versions n/a through 2.3, enabling attackers to exploit the input mechanisms used in web page generation, leading to stored XSS attacks. Users of the affected plugin should implement necessary security measures and consider updating to a patched version to mitigate this risk.
Affected Version(s)
Make Section & Column Clickable For Elementor <= n/a