CVE-2025-53463: WordPress HT Mega – Absolute Addons for WPBakery Page Builder Plugin <= 1.0.9 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega – Absolute Addons for WPBakery Page Builder allows DOM-Based XSS. This issue affects HT Mega – Absolute Addons for WPBakery Page Builder: from n/a through 1.0.9.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega – Absolute Addons for WPBakery Page Builder ht-mega-for-wpbakery allows DOM-Based XSS.This issue affects HT Mega – Absolute Addons for WPBakery Page Builder: from n/a through <= 1.0.9.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53463?
CVE-2025-53463 is classified as a critical vulnerability due to its potential to allow DOM-Based XSS attacks.
How do I fix CVE-2025-53463?
To address CVE-2025-53463, update the HT Mega – Absolute Addons for WPBakery Page Builder to the latest version beyond 1.0.9.
What software is affected by CVE-2025-53463?
CVE-2025-53463 affects HT Plugins HT Mega – Absolute Addons for WPBakery Page Builder versions up to and including 1.0.9.
What type of vulnerability is CVE-2025-53463?
CVE-2025-53463 is classified as a Cross-site Scripting (XSS) vulnerability.
Can CVE-2025-53463 be exploited remotely?
Yes, CVE-2025-53463 can be exploited remotely by attackers through crafted input that triggers the XSS vulnerability.