Ultimate Addons for Elementor Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Ultimate Addons for Elementor WordPress plugin, affecting versions prior to 2.5.0. The issue arises because the plugin does not properly sanitize SVG file contents when these files are uploaded via the xmlrpc.php endpoint using base64 encoding.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded SVG files can contain malicious scripts that are executed when the file is accessed.

Remediation

Users are advised to update the Ultimate Addons for Elementor WordPress plugin to version 2.5.0 or later.

Added: Oct 6, 2025, 6:24 AM
Updated: Oct 6, 2025, 6:24 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
1.7
exploitability
6.8
remediation
7.7
relevance
0.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.