CVE-2025-24752: WordPress Essential Addons for Elementor plugin <= 6.0.14 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Reflected XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.0.14.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24752?
CVE-2025-24752 is classified as a reflected cross-site scripting (XSS) vulnerability, which can potentially lead to data theft or unauthorized actions.
Which versions of Essential Addons for Elementor are affected by CVE-2025-24752?
CVE-2025-24752 affects Essential Addons for Elementor versions from n/a to 6.0.14.
How do I fix CVE-2025-24752?
To fix CVE-2025-24752, update the Essential Addons for Elementor plugin to the latest available version that is above 6.0.14.
What types of attacks can CVE-2025-24752 facilitate?
CVE-2025-24752 can facilitate reflected XSS attacks, allowing attackers to inject malicious scripts into web pages.
Is the CVE-2025-24752 vulnerability specific to any particular platform?
Yes, CVE-2025-24752 is specific to the WordPress platform, affecting the Essential Addons for Elementor plugin.