First published: Wed May 07 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1017.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WProyal Royal Elementor Addons | <=1.7.1017 | |
WP Royal Royal Elementor Kit | <=1.7.1017 |
Update the WordPress Royal Elementor Addons plugin to the latest available version (at least 1.7.1018).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-39361 is classified as a high severity vulnerability due to its potential impact on user data through stored XSS attacks.
To fix CVE-2025-39361, update the Royal Elementor Addons plugin to version 1.7.1018 or later.
CVE-2025-39361 affects the Royal Elementor Addons version 1.7.1017 and earlier.
Yes, CVE-2025-39361 can lead to data loss if an attacker exploits the stored XSS vulnerability to manipulate user data.
CVE-2025-39361 can be relatively easy to exploit for attackers familiar with XSS techniques.