CVE-2025-1458

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 26, 2025
Updated: May 6, 2025
CWE ID 79

Summary

CVE-2025-1458 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Element Pack Addons for Elementor plugin for WordPress. This issue, present in versions up to and including 5.10.29, allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into several widgets, including Dual Button, Creative Button, and Image Stack. These scripts will execute whenever an unsuspecting user views an injected page, potentially leading to security breaches and unintended functionality. This vulnerability arises due to inadequate input sanitization and output escaping.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share