Cross-Site Scripting Vulnerability in Master Addons for Elementor by Liton Arefin
CVE-2025-63055
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-63055?
A vulnerability exists in the Master Addons for Elementor plugin, created by Liton Arefin, allowing for Stored Cross-Site Scripting (XSS) attacks. Attackers can potentially exploit this flaw by injecting malicious scripts, which would be executed when users interact with the affected web pages. This poses significant risks to user data integrity and security, particularly in WordPress environments. Website administrators using affected versions should take immediate action to mitigate these risks by updating to the latest version or applying necessary patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Master Addons for Elementor <= n/a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved