CVE-2025-63026: WordPress Grand Restaurant Theme Elements for Elementor plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant Theme Elements for Elementor grandrestaurant-elementor allows Stored XSS.This issue affects Grand Restaurant Theme Elements for Elementor: from n/a through <= 2.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63026?
CVE-2025-63026 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2025-63026?
To fix CVE-2025-63026, update the Grand Restaurant Theme Elements for Elementor plugin to version 2.1.2 or later.
What types of sites are affected by CVE-2025-63026?
CVE-2025-63026 affects WordPress sites using the Grand Restaurant Theme Elements for Elementor plugin version 2.1.1 and earlier.
What can attackers achieve through CVE-2025-63026?
Attackers can exploit CVE-2025-63026 to execute malicious scripts in the context of users' browsers, potentially stealing data or hijacking sessions.
Is there a workaround for CVE-2025-63026 if I cannot update?
If unable to update, consider disabling the Grand Restaurant Theme Elements for Elementor plugin as a temporary workaround to mitigate risks from CVE-2025-63026.