First published: Thu Mar 27 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Addons for Elementor allows Stored XSS. This issue affects SKT Addons for Elementor: from n/a through 3.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
SKT Addons for Elementor | <=3.5 |
Update the WordPress SKT Addons for Elementor plugin to the latest available version (at least 3.6).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30812 is classified as a high severity vulnerability due to its potential for stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-30812, update SKT Addons for Elementor to the latest version beyond 3.5 where the vulnerability is patched.
CVE-2025-30812 affects SKT Addons for Elementor versions from n/a up to and including 3.5.
CVE-2025-30812 is an improper neutralization of input during web page generation vulnerability, also known as Stored Cross-site Scripting (XSS).
Yes, CVE-2025-30812 can be exploited remotely, allowing attackers to inject malicious scripts that can be executed on the client’s browser.