CVE-2025-1663: Unlimited Elements For Elementor <= 1.5.142 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.142 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1663?
The severity of CVE-2025-1663 is considered medium due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2025-1663?
To fix CVE-2025-1663, update the Unlimited Elements For Elementor plugin to version 1.5.143 or later.
Who is affected by CVE-2025-1663?
All users of the Unlimited Elements For Elementor plugin for WordPress up to version 1.5.142 are affected by CVE-2025-1663.
What type of vulnerability is CVE-2025-1663?
CVE-2025-1663 is a stored cross-site scripting vulnerability that affects certain widgets in the plugin.
Can unauthenticated users exploit CVE-2025-1663?
No, CVE-2025-1663 can only be exploited by authenticated attackers.