First published: Wed Jan 15 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aiwp Elementor AI Addons allows DOM-Based XSS.This issue affects Elementor AI Addons: from n/a through 2.2.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Elementor ai Addons | <=2.2.1 | |
Elementor | <=2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22758 is classified as a moderate severity vulnerability due to its potential for exploitation via DOM-Based XSS.
To fix CVE-2025-22758, users should update the Elementor AI Addons plugin to the latest version beyond 2.2.1.
CVE-2025-22758 affects Elementor AI Addons versions from n/a up to and including 2.2.1.
CVE-2025-22758 is an Improper Neutralization of Input During Web Page Generation vulnerability, resulting in Cross-site Scripting (XSS).
Yes, if you are using Elementor AI Addons version 2.2.1 or earlier, your website may be vulnerable to exploitation through this Cross-site Scripting vulnerability.