First published: Thu Jan 09 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs News Ticker Widget for Elementor allows Stored XSS.This issue affects News Ticker Widget for Elementor: from n/a through 1.3.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Plugin Devs News Ticker for Elementor | <=1.3.2 | |
FlickDevs News Ticker Widget for Elementor | <=1.3.2 |
Update the WordPress News Ticker Widget for Elementor wordpress plugin to the latest available version (at least 1.3.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22812 has a high severity rating due to its potential for stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-22812, update the FlickDevs News Ticker Widget for Elementor to version 1.3.3 or later.
CVE-2025-22812 affects all versions of the FlickDevs News Ticker Widget for Elementor from n/a through 1.3.2.
In CVE-2025-22812, Cross-site Scripting (XSS) refers to the vulnerability that allows attackers to inject malicious scripts into web pages viewed by users.
Yes, the WordPress News Ticker Widget for Elementor is also affected by CVE-2025-22812 up to version 1.3.2.