CVE-2025-26745
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 15, 2025
CWE ID 79
Summary
CVE-2025-26745 is a Cross-site Scripting (XSS) vulnerability affecting RS Elements Elementor Addon. The flaw, which allows Stored XSS, occurs during web page generation in RS Elements Elementor Addon, from version n/a through 1.1.5. An attacker can exploit this vulnerability by injecting malicious scripts into a webpage, which can steal user data, manipulate webpage functionality, or carry out other malicious activities. Users are advised to upgrade to the latest version of RS Elements Elementor Addon to address this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.