CVE-2025-32184: WordPress Ultimate Store Kit Elementor Addons plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.5.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32184?
CVE-2025-32184 has a high severity due to its potential to allow stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-32184?
To fix CVE-2025-32184, you should update the Ultimate Store Kit Elementor Addons to the latest version above 2.4.0.
Who is affected by CVE-2025-32184?
CVE-2025-32184 affects users of bdthemes Ultimate Store Kit Elementor Addons versions up to and including 2.4.0.
What type of vulnerability is CVE-2025-32184?
CVE-2025-32184 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
What are the potential impacts of CVE-2025-32184?
The potential impacts of CVE-2025-32184 include unauthorized actions performed by users and data exposure due to malicious scripts.