Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Stored XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.3.3.
Published: 2025-01-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that allows attackers to inject malicious scripts into the web page output. By embedding crafted JavaScript in the plugin’s content fields, an attacker can cause arbitrary code to run in the browsers of any visitor who views the affected content. The impact can range from cookie theft and session hijacking to defacement or remote code execution within the user’s session, depending on the attacker’s payload.

Affected Systems

Element Invader’s ElementInvader Addons for Elementor plugin for WordPress is affected. Versions from the earliest release through 1.3.3 contain the flaw. Users running any of these versions should review which plugin versions are installed.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score is reported as less than 1%, meaning that although the vulnerability exists, the likelihood of real‑world exploitation is currently very low. The plugin is not listed in the CISA KEV catalog, so it is not known to be actively exploited in the wild. The description identifies the flaw as a stored XSS vulnerability; based on this, it is inferred that an attacker would need to inject malicious payloads that are stored and later rendered to visitors, likely via the plugin’s administrative interface or a similarly privileged input point, although the exact attack vector is not explicitly stated. Once stored, the malicious script executes whenever a user loads the affected page, making the attack both persistent and broadly visible.

Generated by OpenCVE AI on May 2, 2026 at 09:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor-provided patch to update Element Invader Addons for Elementor to the latest available version.
  • Sanitize or encode any user‑supplied content that is stored by the plugin to eliminate executable script code.
  • If a patch cannot be applied immediately, disable or uninstall the vulnerable plugin to prevent the execution of stored scripts until the fix is installed.

Generated by OpenCVE AI on May 2, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3921 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows Stored XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows Stored XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Stored XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.3.3.
First Time appeared Elementinvader
Elementinvader elementinvader Addons For Elementor
CPEs cpe:2.3:a:elementinvader:elementinvader_addons_for_elementor:*:*:*:*:*:wordpress:*:*
Vendors & Products Elementinvader
Elementinvader elementinvader Addons For Elementor
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows Stored XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.3.
Title WordPress ElementInvader Addons for Elementor plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Elementinvader Elementinvader Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:33.491Z

Reserved: 2025-01-23T14:52:44.768Z

Link: CVE-2025-24729

cve-icon Vulnrichment

Updated: 2025-02-12T19:54:38.913Z

cve-icon NVD

Status : Modified

Published: 2025-01-24T18:15:47.037

Modified: 2026-04-23T15:25:23.580

Link: CVE-2025-24729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:30:20Z

Weaknesses