CVE Details
Basic Information
| Title | Exclusive Addons for Elementor <= 2.7.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown |
|---|---|
| Type | cve |
| Published | 2025-08-06T03:41:00.255Z |
| Modified | 2025-08-06T03:41:00.255Z |
Product Information
| Vendor | timstrifler |
|---|---|
| Product | Exclusive Addons for Elementor |
| Version | * |
CVSS Information
| Base Score | 6.4 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
AI Analysis
| AI Description | A stored cross-site scripting (XSS) vulnerability in the Exclusive Addons for Elementor WordPress plugin (versions up to 2.7.9.4) allows authenticated attackers with Contributor-level access to inject malicious scripts, which execute when users access the compromised page. |
|---|---|
| AI Severity | Medium |
| AI Vendor | WordPress Community |
| AI Product | Exclusive Addons for Elementor |
| AI Version | <=2.7.9.4 |
Affected Products
- timstrifler Exclusive Addons for Elementor *
Additional Information
| CWE List | CWE-79 |
|---|---|
| Source | Wordfence |
Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, 2.7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/51d3d738-5c82-4f6b-b8f3-d5af5391b6f6?source=cve
- https://plugins.trac.wordpress.org/browser/exclusive-addons-for-elementor/trunk/assets/vendor/js/jquery.countdown.min.js
- https://plugins.trac.wordpress.org/browser/exclusive-addons-for-elementor/trunk/assets/js/exad-scripts.js#L187
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3326867@exclusive-addons-for-elementor&new=3326867@exclusive-addons-for-elementor&sfp_email=&sfph_mail=