First published: Wed Apr 09 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor One Click Accessibility allows Stored XSS. This issue affects One Click Accessibility: from n/a through 3.1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor One Click Accessibility | <=3.1.0 | |
WordPress One Click Accessibility | <=3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32640 has been classified as a moderate severity vulnerability due to its potential to allow stored cross-site scripting (XSS) attacks.
To fix CVE-2025-32640, upgrade Elementor One Click Accessibility to version 3.1.1 or later.
CVE-2025-32640 affects Elementor One Click Accessibility and WordPress One Click Accessibility up to version 3.1.0.
CVE-2025-32640 is a Cross-site Scripting (XSS) vulnerability, specifically a Stored XSS issue.
Yes, CVE-2025-32640 can lead to data exposure as it allows attackers to execute malicious scripts in the context of the user's browser.