Cross-Site Scripting Vulnerability in WPZOOM Addons for Elementor
CVE-2025-67951
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 December 2025
What is CVE-2025-67951?
A Cross-Site Scripting (XSS) vulnerability has been identified in WPZOOM Addons for Elementor, allowing attackers to inject malicious scripts into web pages viewed by users. This issue arises from improper handling of user input during the generation of web content, specifically affecting versions of the plugin up to 1.2.10. Exploiting this vulnerability could lead to unauthorized access to sensitive data or unauthorized actions taken by users. Website administrators using this plugin should ensure they upgrade to the latest version or take appropriate mitigation measures.
Affected Version(s)
WPZOOM Addons for Elementor <= n/a