Cross-site Scripting Vulnerability in WPDeveloper Essential Addons for Elementor
CVE-2025-69092
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 December 2025
What is CVE-2025-69092?
A Cross-site Scripting (XSS) vulnerability exists in the WPDeveloper Essential Addons for Elementor plugin, allowing attackers to manipulate web page content. This flaw arises from improper input neutralization during page generation, potentially enabling DOM-based XSS attacks. Users of versions n/a through 6.5.3 are particularly affected, which can lead to unauthorized script execution and may compromise site integrity and user data security.
Affected Version(s)
Essential Addons for Elementor 0 <= 6.5.3