CVE-2025-49235: WordPress RTMKit Addons for Elementor plugin <= 1.6.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit Addons for Elementor allows Stored XSS. This issue affects RTMKit Addons for Elementor: from n/a through 1.6.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Stored XSS.This issue affects RTMKit: from n/a through <= 1.6.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49235?
CVE-2025-49235 has a high severity due to its potential for stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-49235?
To fix CVE-2025-49235, update the RTMKit Addons for Elementor to version 1.6.1 or later.
What does CVE-2025-49235 exploit?
CVE-2025-49235 exploits improper neutralization of user input during web page generation, allowing for stored XSS.
Which versions are affected by CVE-2025-49235?
CVE-2025-49235 affects all versions of RTMKit Addons for Elementor from n/a up to and including 1.6.0.
What are the potential impacts of CVE-2025-49235?
The potential impacts of CVE-2025-49235 include unauthorized data access and user data manipulation through malicious scripts.