CVE-2025-26745

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 15, 2025
CWE ID 79

Summary

CVE-2025-26745 is a Cross-site Scripting (XSS) vulnerability affecting RS Elements Elementor Addon. The flaw, which allows Stored XSS, occurs during web page generation in RS Elements Elementor Addon, from version n/a through 1.1.5. An attacker can exploit this vulnerability by injecting malicious scripts into a webpage, which can steal user data, manipulate webpage functionality, or carry out other malicious activities. Users are advised to upgrade to the latest version of RS Elements Elementor Addon to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share