CVE-2025-12837: aThemes Addons for Elementor <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Call To Action Widget
The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user-supplied values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12837?
CVE-2025-12837 has a medium severity rating due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-12837?
To remediate CVE-2025-12837, update the aThemes Addons for Elementor plugin to version 1.1.6 or later.
Who is affected by CVE-2025-12837?
CVE-2025-12837 affects users of the aThemes Addons for Elementor plugin for WordPress version 1.1.5 and earlier.
What is the impact of CVE-2025-12837?
CVE-2025-12837 allows authenticated users to inject malicious scripts into the website through the Call To Action widget.
How does CVE-2025-12837 occur?
CVE-2025-12837 occurs due to insufficient input sanitization and output escaping on user-supplied values.