Stored Cross-Site Scripting Vulnerability in Plus Addons for Elementor by WPDeveloper
CVE-2025-9698
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 October 2025
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2025-9698?
The Plus Addons for Elementor plugin before version 6.3.16 is vulnerable to stored cross-site scripting (XSS) attacks due to inadequate sanitation of SVG file contents. This flaw allows users with minimal privilege, like those with an Author role, to inject malicious scripts that can be executed in the context of other users. Proper precautions must be taken to secure this plugin and ensure that all user inputs are appropriately validated and sanitized.
Affected Version(s)
The Plus Addons for Elementor 0 < 6.3.16
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.