CVE-2025-54704: WordPress Easy Elementor Addons plugin <= 2.2.6 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy Elementor Addons allows DOM-Based XSS. This issue affects Easy Elementor Addons: from n/a through 2.2.6.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons allows DOM-Based XSS.This issue affects Easy Elementor Addons: from n/a through <= 2.2.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54704?
CVE-2025-54704 is classified as a medium severity vulnerability due to its potential for causing DOM-Based XSS attacks.
How do I fix CVE-2025-54704?
To mitigate CVE-2025-54704, update the Easy Elementor Addons plugin to a version beyond 2.2.6.
What applications are affected by CVE-2025-54704?
CVE-2025-54704 affects the Easy Elementor Addons plugin versions up to and including 2.2.6.
What type of attack does CVE-2025-54704 enable?
CVE-2025-54704 enables Cross-site Scripting (XSS), specifically DOM-Based XSS attacks.
Who is the vendor responsible for CVE-2025-54704?
The vendor responsible for CVE-2025-54704 is Hashthemes, the creator of the Easy Elementor Addons plugin.