Stored Cross-Site Scripting Vulnerability in Magic Buttons for Elementor Plugin by WordPress
CVE-2025-6687
6.4MEDIUM
What is CVE-2025-6687?
The Magic Buttons for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping for user-supplied attributes in its magic-button shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject malicious scripts into web pages. These scripts would execute when a user visits the compromised page, potentially leading to data theft or unauthorized actions performed on behalf of the user.
Affected Version(s)
Magic Buttons for Elementor * <= 1.0