Stored Cross-Site Scripting Vulnerability in X Addons for Elementor by WordPress
CVE-2025-9204
6.4MEDIUM
What is CVE-2025-9204?
The X Addons for Elementor plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability. Specifically, the issue arises from inadequate input sanitization and output escaping on the Youtube Video ID field. This vulnerability enables authenticated attackers with contributor-level access or higher to inject malicious scripts into pages. The exploits can be executed whenever a user visits an affected page, potentially compromising user data and website integrity.
Affected Version(s)
X Addons for Elementor * <= 1.0.14