CVE-2025-22312
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 7, 2025
CWE ID 79
Summary
CVE-2025-22312 is a Cross-site Scripting (XSS) vulnerability affecting the ThimPress Thim Elementor Kit. The flaw, which is DOM-Based, allows unauthorized attackers to inject malicious scripts into web pages generated by the plugin. This can lead to the theft of user data or the execution of malicious code. The vulnerability exists in versions of the Thim Elementor Kit from n/a through 1.2.8. Users are strongly advised to update to the latest version or consider alternative solutions to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Thim Elementor Kit Plugin
Affected Vendors
- ThimPress