Cross-Site Scripting Vulnerability in Xpro Elementor Addons by Xpro
CVE-2025-63044
6.5MEDIUM
What is CVE-2025-63044?
A vulnerability in the Xpro Elementor Addons allows for DOM-based Cross-site Scripting (XSS) attacks due to improper handling of user input. This flaw exists in versions earlier than 1.4.19.1, making it possible for attackers to inject malicious scripts into web pages viewed by other users. Exploiting this vulnerability could lead to data theft, unauthorized actions, and compromised user sessions, highlighting the importance of immediate updates and proper input sanitization.
Affected Version(s)
Xpro Elementor Addons <= n/a