CVE-2025-53199: WordPress HT Slider For Elementor plugin <= 1.6.5 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Slider For Elementor allows DOM-Based XSS. This issue affects HT Slider For Elementor: from n/a through 1.6.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Slider For Elementor ht-slider-for-elementor allows DOM-Based XSS.This issue affects HT Slider For Elementor: from n/a through <= 1.6.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53199?
CVE-2025-53199 is classified as a high severity vulnerability due to its potential for exploitation via DOM-based cross-site scripting.
How do I fix CVE-2025-53199?
To fix CVE-2025-53199, update the HT Slider For Elementor plugin to version 1.6.6 or later.
What software is affected by CVE-2025-53199?
CVE-2025-53199 affects HT Slider For Elementor versions from n/a up to 1.6.5.
What type of vulnerability is CVE-2025-53199?
CVE-2025-53199 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as Cross-site Scripting (XSS).
Can CVE-2025-53199 be exploited remotely?
Yes, CVE-2025-53199 can be exploited remotely by injecting malicious scripts into the affected web pages.