CVE-2025-7498: Exclusive Addons for Elementor <= 2.7.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, 2.7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7498?
CVE-2025-7498 has a critical severity rating due to its potential for exploitation leading to Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-7498?
To fix CVE-2025-7498, update the Exclusive Addons for Elementor plugin to version 2.8 or later.
What impacts does CVE-2025-7498 have on my website?
CVE-2025-7498 can allow authenticated attackers to inject malicious scripts, affecting user sessions and website integrity.
Can CVE-2025-7498 be exploited without authentication?
No, CVE-2025-7498 requires an authenticated user to exploit the vulnerability.
Which versions of Exclusive Addons for Elementor are affected by CVE-2025-7498?
All versions up to and including 2.7.9.4 of Exclusive Addons for Elementor are affected by CVE-2025-7498.