CVE-2025-26761: WordPress Easy Elementor Addons plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons allows DOM-Based XSS.This issue affects Easy Elementor Addons: from n/a through <= 2.1.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26761?
CVE-2025-26761 is classified as a critical severity vulnerability due to the potential for DOM-Based XSS attacks.
How do I fix CVE-2025-26761?
To fix CVE-2025-26761, update HashThemes Easy Elementor Addons to the latest version beyond 2.1.5.
What type of vulnerability is CVE-2025-26761?
CVE-2025-26761 is a Cross-site Scripting (XSS) vulnerability that results from improper neutralization of input during web page generation.
What software is affected by CVE-2025-26761?
CVE-2025-26761 affects HashThemes Easy Elementor Addons versions up to and including 2.1.5.
Does CVE-2025-26761 affect any other products?
CVE-2025-26761 affects the WordPress Easy Elementor Addons plugin specifically.