Cross-Site Scripting Vulnerability in WPZOOM Addons for Elementor
CVE-2025-67951
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 December 2025
What is CVE-2025-67951?
A Cross-Site Scripting (XSS) vulnerability has been identified in WPZOOM Addons for Elementor, allowing attackers to inject malicious scripts into web pages viewed by users. This issue arises from improper handling of user input during the generation of web content, specifically affecting versions of the plugin up to 1.2.10. Exploiting this vulnerability could lead to unauthorized access to sensitive data or unauthorized actions taken by users. Website administrators using this plugin should ensure they upgrade to the latest version or take appropriate mitigation measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPZOOM Addons for Elementor <= n/a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved