First published: Tue Apr 22 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in page for Elementor allows DOM-Based XSS. This issue affects Post in page for Elementor: from n/a through 1.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Post in page for Elementor | <=1.0.1 |
Update the WordPress Post in page for Elementor plugin to the latest available version (at least 1.0.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46225 is considered a high severity vulnerability due to the potential for DOM-Based Cross-site Scripting (XSS).
To fix CVE-2025-46225, update the Post in page for Elementor plugin to version 1.0.2 or later.
CVE-2025-46225 allows attackers to perform Cross-site Scripting (XSS) attacks, potentially leading to unauthorized access or data theft.
CVE-2025-46225 affects versions of the Post in page for Elementor plugin up to and including 1.0.1.
All users of the Post in page for Elementor plugin version 1.0.1 or earlier are affected by CVE-2025-46225.