6.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Description
The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author to perform Stored Cross-Site Scripting attacks.
Basic Information
ID
CVE-2025-9698
Source
WPScan
Published
Oct 13, 2025 at 06:00
Modified
Oct 14, 2025 at 20:25
Affected Product
Vendor
Unknown
Product
The Plus Addons for Elementor
Affected Versions
Unknown The Plus Addons for Elementor 0