CVE-2025-22806: WordPress Black Widgets For Elementor plugin <= 1.3.8 - Cross Site Scripting (XSS) vulnerability
Published Jan 9, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor black-widgets allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through <= 1.3.8.
Affected Software
3 affected components
Modernaweb Black Widgets For Elementor Wordpress<1.3.9
Modernaweb Black Widgets For Elementor<=1.3.8
WordPress Black Widgets For Elementor<=1.3.8
Remediation
Information
Update the WordPress Black Widgets For Elementor wordpress plugin to the latest available version (at least 1.3.9).
Event History
Jan 9, 2025
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22806?
CVE-2025-22806 is a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2025-22806?
To fix CVE-2025-22806, update Black Widgets For Elementor to version 1.3.9 or later.
3
What type of vulnerability is CVE-2025-22806?
CVE-2025-22806 is classified as a DOM-Based Cross-Site Scripting (XSS) vulnerability.
4
Which versions of Black Widgets For Elementor are affected by CVE-2025-22806?
CVE-2025-22806 affects Black Widgets For Elementor versions up to and including 1.3.8.
5
What impact does CVE-2025-22806 have on users?
CVE-2025-22806 could allow attackers to execute arbitrary JavaScript in the context of the user’s browser session.