A critical security vulnerability in the Essential Addons for Elementor plugin (CVE-2025-24752) has put over two million WordPress websites at risk of cross-site scripting (XSS) attacks. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The web development community can mitigate risks in an increasingly hostile digital landscape by prioritizing security hygiene and adopting a zero-trust approach to user inputs. The vulnerability discovered in the plugin’s handling of user inputs allowed attackers to inject malicious scripts through crafted URLs. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. The plugin enhances WordPress sites by providing 100+ design elements, including advanced data tables, WooCommerce integrations, and dynamic galleries. The vulnerability stemmed from improper sanitization of the popup-selector query parameter in the plugin’s src/js/view/general.js file. The flawed code replaced underscores with spaces but failed to sanitize other dangerous characters, enabling script execution in victims’ browsers. WPDeveloper addressed the flaw in version 6.0.15 by implementing strict input validation for the popup-selector parameter.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 26 Feb 2025 09:05:15 +0000