216.73.216.197

CVE-2025-9698

· Published 13/10/2025 06:15 · Modified 13/10/2025 06:15

Labels: CVE-2025-9698 2025-10-13CVE-2025-9698[email protected]

Essential information

Published
13/10/2025 06:15
Modified
13/10/2025 06:15
Author
Creator
CISA KEV
No
CWE

Description

The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author to perform Stored Cross-Site Scripting attacks.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / plus addons for elementor cpe:2.3:a:wordpress:plus_addons_for_elementor:<6.3.16:*:*:*:*:*:*:*

References