CVE-2025-24752
HIGH EXPLOITED NUCLEIWpdeveloper Essential Addons For Elementor < 6.0.15 - XSS
Title source: ruleDescription
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Reflected XSS. This issue affects Essential Addons for Elementor: from n/a through 6.0.14.
Exploits (2)
nomisec
WORKING POC
6 stars
by Sachinart · client-side
https://github.com/Sachinart/essential-addons-for-elementor-xss-poc
Nuclei Templates (1)
Essential Addons for Elementor < 6.0.15 - Cross-Site Scripting
MEDIUMVERIFIEDby DhiyaneshDK
FOFA:
body="/wp-content/plugins/essential-addons-for-elementor-lite"
Scores
CVSS v3
7.1
EPSS
0.0241
EPSS Percentile
84.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Exploitation Intel
VulnCheck KEV
2025-02-04
Classification
CWE
CWE-79
Status
published
Affected Products (1)
wpdeveloper/essential_addons_for_elementor
< 6.0.15
Timeline
Published
Apr 17, 2025
Tracked Since
Feb 18, 2026