CVE-2025-9703
BaseFortify
Publication date: 2025-10-06
Last updated on: 2025-10-06
Assigner: WPScan
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ultimate_addons | elementor | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Ultimate Addons for Elementor WordPress plugin before version 2.5.0. It occurs because the plugin does not sanitize the contents of SVG files when they are uploaded through the xmlrpc.php endpoint using base64 encoding. This lack of sanitization allows an attacker to inject malicious scripts, leading to a Cross-Site Scripting (XSS) vulnerability.
How can this vulnerability impact me? :
The vulnerability can allow attackers to execute malicious scripts in the context of the affected website. This can lead to unauthorized actions such as stealing user session cookies, defacing the website, redirecting users to malicious sites, or performing other malicious activities that compromise the security and integrity of the website and its users.