CVE-2025-46472: WordPress The Pack Elementor addons plugin <= 2.1.6 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon The Pack Elementor addons allows Stored XSS. This issue affects The Pack Elementor addons: from n/a through 2.1.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon The Pack Elementor addons the-pack-addon allows Stored XSS.This issue affects The Pack Elementor addons: from n/a through <= 2.1.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46472?
CVE-2025-46472 has a critical severity level due to its potential for Stored Cross-site Scripting (XSS).
How do I fix CVE-2025-46472?
To fix CVE-2025-46472, update The Pack Elementor addons to version 2.1.3 or later, as it addresses the vulnerability.
What type of vulnerability is CVE-2025-46472?
CVE-2025-46472 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
Which versions of The Pack Elementor addons are affected by CVE-2025-46472?
CVE-2025-46472 affects versions of The Pack Elementor addons from n/a through 2.1.2.
Who is the vendor for the software affected by CVE-2025-46472?
The vendor for the software affected by CVE-2025-46472 is webangon.