Stored Cross-Site Scripting Vulnerability in Plus Addons for Elementor by WPDeveloper
CVE-2025-9698

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 October 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-9698?

The Plus Addons for Elementor plugin before version 6.3.16 is vulnerable to stored cross-site scripting (XSS) attacks due to inadequate sanitation of SVG file contents. This flaw allows users with minimal privilege, like those with an Author role, to inject malicious scripts that can be executed in the context of other users. Proper precautions must be taken to secure this plugin and ensure that all user inputs are appropriately validated and sanitized.

Affected Version(s)

The Plus Addons for Elementor 0 < 6.3.16

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tan Nguyen
WPScan
.
CVE-2025-9698 : Stored Cross-Site Scripting Vulnerability in Plus Addons for Elementor by WPDeveloper