PT-2025-32098 · WordPress+1 · Exclusive Addons For Elementor+1

Craig Smith

·

Published

2025-08-06

·

Updated

2025-08-12

·

CVE-2025-7498

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Exclusive Addons for Elementor versions up to and including 2.7.9.4
Description The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting through the Countdown Widget due to insufficient input sanitization and output escaping. This allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages, which will execute when a user accesses an injected page.
Recommendations Update Exclusive Addons for Elementor to a version later than 2.7.9.4.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-7498

Affected Products

Elementor
Exclusive Addons For Elementor