Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for-elementor-lite allows Stored XSS.This issue affects aThemes Addons for Elementor: from n/a through <= 1.0.8.
Published: 2025-03-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation flaw in the WordPress aThemes Addons for Elementor plugin allows stored cross‑site scripting content to be executed when users view pages that include data supplied through the plugin. The attack vector is inferred to be the plugin’s data input interfaces, as the vulnerability is described as stored XSS: user supplied data is not sanitized before being saved to the database and later rendered in page markup, enabling the injection of arbitrary JavaScript. The impact is that any visitor or user whose browser renders a page containing the malicious content could have its session hijacked, sensitive data exfiltrated, or be exposed to phishing or malware.

Affected Systems

The vulnerability affects the WordPress plugin Syed Balkhi aThemes Addons for Elementor. All released versions up to and including 1.0.8 are impacted; newer releases are not listed as vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The stored nature of the flaw means that once malicious content is inserted, it will persist and affect any site visitor, making it a significant risk if the plugin is enabled on a website.

Generated by OpenCVE AI on May 2, 2026 at 03:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the aThemes Addons for Elementor plugin to a version newer than 1.0.8.
  • If an update is not yet available, disable or uninstall the plugin until a fix is released.
  • Implement a strict Content Security Policy to mitigate the impact of any existing injected scripts as a temporary measure.

Generated by OpenCVE AI on May 2, 2026 at 03:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8483 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemes aThemes Addons for Elementor allows Stored XSS.This issue affects aThemes Addons for Elementor: from n/a through 1.0.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemes aThemes Addons for Elementor allows Stored XSS.This issue affects aThemes Addons for Elementor: from n/a through 1.0.8. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for-elementor-lite allows Stored XSS.This issue affects aThemes Addons for Elementor: from n/a through <= 1.0.8.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Thu, 29 May 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Athemes
Athemes athemes Addons For Elementor
CPEs cpe:2.3:a:athemes:athemes_addons_for_elementor:*:*:*:*:free:wordpress:*:*
Vendors & Products Athemes
Athemes athemes Addons For Elementor

Thu, 27 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemes aThemes Addons for Elementor allows Stored XSS.This issue affects aThemes Addons for Elementor: from n/a through 1.0.8.
Title WordPress aThemes Addons for Elementor plugin <= 1.0.8 - Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Athemes Athemes Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T23:55:58.194Z

Reserved: 2025-01-07T21:02:36.083Z

Link: CVE-2025-22646

cve-icon Vulnrichment

Updated: 2025-03-27T15:22:58.928Z

cve-icon NVD

Status : Modified

Published: 2025-03-27T15:15:57.397

Modified: 2026-04-23T15:23:19.240

Link: CVE-2025-22646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:15:06Z

Weaknesses