A Cross-Site Scripting (XSS) vulnerability exists in Essential Addons for Elementor Plugin for WordPress versions prior to 6.0.15. The vulnerability allows an attacker to inject malicious JavaScript payloads into web pages by exploiting insufficient input sanitization and output escaping in specific plugin components.
id: CVE-2025-24752
info:
name: Essential Addons for Elementor < 6.0.15 - Cross-Site Scripting
a
...