CVE-2025-58017: WordPress Ultimate Store Kit Elementor Addons plugin <= 2.8.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.8.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.8.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58017?
CVE-2025-58017 is classified as a high severity vulnerability due to the risk of stored Cross-site Scripting (XSS).
How do I fix CVE-2025-58017?
To fix CVE-2025-58017, update the Ultimate Store Kit Elementor Addons to version 2.8.3 or later.
What type of vulnerability is CVE-2025-58017?
CVE-2025-58017 is an improper neutralization of input during web page generation that leads to stored Cross-site Scripting (XSS).
Which versions of the Ultimate Store Kit Elementor Addons are affected by CVE-2025-58017?
CVE-2025-58017 affects Ultimate Store Kit Elementor Addons versions up to and including 2.8.2.
Who is the vendor of the software affected by CVE-2025-58017?
The vendor of the affected software is bdthemes.