CVE-2025-30812: WordPress SKT Addons for Elementor plugin <= 3.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Addons for Elementor skt-addons-for-elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through <= 3.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30812?
CVE-2025-30812 is classified as a high severity vulnerability due to its potential for stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-30812?
To fix CVE-2025-30812, update SKT Addons for Elementor to the latest version beyond 3.5 where the vulnerability is patched.
What versions of SKT Addons for Elementor are affected by CVE-2025-30812?
CVE-2025-30812 affects SKT Addons for Elementor versions from n/a up to and including 3.5.
What type of vulnerability is CVE-2025-30812?
CVE-2025-30812 is an improper neutralization of input during web page generation vulnerability, also known as Stored Cross-site Scripting (XSS).
Can CVE-2025-30812 be exploited remotely?
Yes, CVE-2025-30812 can be exploited remotely, allowing attackers to inject malicious scripts that can be executed on the client’s browser.