First published: Fri Jan 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows DOM-Based XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
ElementInvader Addons for Elementor | <=1.3.0 | |
ElementInvader Addons for Elementor | <=1.3.0 |
Update the WordPress ElementInvader Addons for Elementor plugin to the latest available version (at least 1.3.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24578 is classified as a medium severity vulnerability due to its potential for causing cross-site scripting (XSS) attacks.
To fix CVE-2025-24578, update the ElementInvader Addons for Elementor to the latest version beyond 1.3.0.
CVE-2025-24578 is an improper neutralization of input during web page generation, allowing for DOM-based XSS.
CVE-2025-24578 affects all versions of ElementInvader Addons for Elementor up to and including version 1.3.0.
Users of ElementInvader Addons for Elementor on WordPress who have not updated beyond version 1.3.0 are vulnerable to CVE-2025-24578.