CVE-2025-9703: Ultimate Addons for Elementor Lite < 2.5.0 - Author+ Stored XSS
The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9703?
CVE-2025-9703 is classified as a Cross-Site Scripting vulnerability with a potential for significant impact on affected websites.
How do I fix CVE-2025-9703?
To fix CVE-2025-9703, update the Ultimate Addons for Elementor plugin to version 2.5.0 or later to ensure proper sanitization of SVG file contents.
What versions of Ultimate Addons for Elementor are affected by CVE-2025-9703?
Versions of Ultimate Addons for Elementor prior to 2.5.0 are affected by CVE-2025-9703.
Can CVE-2025-9703 lead to data theft?
Yes, CVE-2025-9703 can lead to data theft through Cross-Site Scripting attacks that exploit the lack of sanitization.
Is it safe to upload SVG files to my website with CVE-2025-9703 present?
No, it is not safe to upload SVG files to your website while CVE-2025-9703 is present due to the risk of XSS vulnerabilities.