CVE-2025-48295: WordPress Easy Elementor Addons plugin <= 2.2.5 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy Elementor Addons allows Stored XSS. This issue affects Easy Elementor Addons: from n/a through 2.2.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons allows Stored XSS.This issue affects Easy Elementor Addons: from n/a through <= 2.2.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48295?
CVE-2025-48295 is classified as a high-severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-48295?
To mitigate CVE-2025-48295, upgrade Easy Elementor Addons to version 2.2.6 or later where the vulnerability has been patched.
What versions of Easy Elementor Addons are affected by CVE-2025-48295?
CVE-2025-48295 affects Easy Elementor Addons versions up to and including 2.2.5.
What type of vulnerability is CVE-2025-48295?
CVE-2025-48295 is an improper neutralization of input during web page generation, leading to a stored XSS vulnerability.
Who is impacted by CVE-2025-48295?
Users of the Easy Elementor Addons plugin for WordPress who are running version 2.2.5 or earlier are impacted by CVE-2025-48295.