CVE-2025-32197
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 79
Summary
CVE-2025-32197 is a Cross-site Scripting (XSS) vulnerability affecting the Piotnet Addons For Elementor plugin. The issue, which is classified as Improper Neutralization of Input During Web Page Generation, can be exploited to inject malicious scripts into web pages viewed by other users. The vulnerability exists in versions of the plugin from n/a through 2.4.34 and can lead to theft of user data or unauthorized actions. Users are advised to update to the latest version of the plugin to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Piotnet Addons for Elementor Plugin
Affected Vendors
- WordPress