Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor sky-elementor-addons allows Stored XSS.This issue affects Sky Addons for Elementor: from n/a through <= 3.0.1.
Published: 2025-04-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Sky Addons for Elementor plugin suffers from improper neutralization of input, allowing attackers to store malicious scripts that are later rendered as part of a web page. This vulnerability can lead to the execution of arbitrary code in the context of an affected user’s browser, exposing the user to credential theft, defacement, or session hijacking. The weakness is classified as CWE‑79, indicating an input‑validation issue that results in XSS.

Affected Systems

WordPress sites that have the wowDevs Sky Addons for Elementor plugin installed in any version up to and including 3.0.1 are affected. No newer version numbers are listed in the current data, so any site with the vulnerable plugin must review patch availability.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests that exploitation is unlikely but possible. The vulnerability is not yet listed in the CISA KEV catalog, meaning no widespread exploitation has been documented, but the stored XSS nature still permits persistent attacks. Attackers would most likely exploit the plug‑in via the content editor or similar input fields that accept user‑supplied data. Based on the description, it is inferred that the likely attack vector is through the editor interface or analogous page‑creation features, as these are the input points used to store content that is subsequently rendered to visitors. The absence of a high exploitation probability does not diminish the potential impact on users encountering the infected page.

Generated by OpenCVE AI on May 1, 2026 at 09:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Sky Addons for Elementor plugin to the latest version that patches the XSS flaw.
  • If an upgrade is unavailable, disable or remove the plugin entirely from the WordPress installation.
  • Block or sanitize any stored content that could be rendered from the plugin until a fix is applied.

Generated by OpenCVE AI on May 1, 2026 at 09:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12077 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor allows Stored XSS. This issue affects Sky Addons for Elementor: from n/a through 3.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor allows Stored XSS. This issue affects Sky Addons for Elementor: from n/a through 3.0.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor sky-elementor-addons allows Stored XSS.This issue affects Sky Addons for Elementor: from n/a through <= 3.0.1.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 25 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor allows Stored XSS. This issue affects Sky Addons for Elementor: from n/a through 3.0.1.
Title WordPress Sky Addons for Elementor plugin <= 3.0.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wowdevs Sky Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:37.061Z

Reserved: 2025-04-22T09:21:51.396Z

Link: CVE-2025-46260

cve-icon Vulnrichment

Updated: 2025-04-24T19:56:25.143Z

cve-icon NVD

Status : Deferred

Published: 2025-04-24T16:15:34.200

Modified: 2026-04-23T15:29:58.360

Link: CVE-2025-46260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T09:15:13Z

Weaknesses