Cross-site Scripting Vulnerability in Envo Extra by EnvoThemes
CVE-2025-66066
6.1MEDIUM
What is CVE-2025-66066?
The Envo Extra plugin from EnvoThemes is susceptible to a Cross-site Scripting (XSS) vulnerability due to improper input sanitization during web page generation. This allows malicious users to inject harmful scripts into web pages that may then be stored and executed in the context of other users' browsers. The vulnerability affects versions of Envo Extra up to and including 1.9.11, highlighting the need for users to regularly update their plugins to safeguard against potential attacks.
Affected Version(s)
Envo Extra <= n/a