First published: Mon Feb 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webilia Inc. Vertex Addons for Elementor allows Stored XSS. This issue affects Vertex Addons for Elementor: from n/a through 1.2.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Webilia Vertex Addons for Elementor | <=1.2.0 | |
WordPress Vertex Addons for Elementor | <=1.2.0 |
Update the WordPress Vertex Addons for Elementor plugin to the latest available version (at least 1.3.0).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26769 is classified as a high-severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
To fix CVE-2025-26769, update the Vertex Addons for Elementor to the latest version beyond 1.2.0.
CVE-2025-26769 can allow malicious users to inject scripts into web pages viewed by other users, leading to data theft or session hijacking.
All versions of Vertex Addons for Elementor up to and including 1.2.0 are affected by CVE-2025-26769.
Yes, CVE-2025-26769 has been reported and noted within the security community as a significant vulnerability related to cross-site scripting.