CVE-2025-39361: WordPress Royal Elementor Addons plugin <= 1.7.1017 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1017.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39361?
CVE-2025-39361 is classified as a high severity vulnerability due to its potential impact on user data through stored XSS attacks.
How do I fix CVE-2025-39361?
To fix CVE-2025-39361, update the Royal Elementor Addons plugin to version 1.7.1018 or later.
What products are affected by CVE-2025-39361?
CVE-2025-39361 affects the Royal Elementor Addons version 1.7.1017 and earlier.
Can CVE-2025-39361 lead to data loss?
Yes, CVE-2025-39361 can lead to data loss if an attacker exploits the stored XSS vulnerability to manipulate user data.
Is CVE-2025-39361 easy to exploit?
CVE-2025-39361 can be relatively easy to exploit for attackers familiar with XSS techniques.