CVE-2025-22786

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 15, 2025
CWE ID 35

Summary

CVE-2025-22786 is a newly disclosed path traversal vulnerability that impacts the ElementInvader Addons for Elementor. This issue allows an attacker to perform PHP Local File Inclusion by exploiting the vulnerable path handling. The vulnerability affects versions of the ElementInvader Addons for Elementor from n/a through 1.2.6. Successful exploitation could lead to the disclosure of sensitive information or even take control of the affected system. Users are urged to update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share