Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs News Ticker Widget for Elementor allows Stored XSS.This issue affects News Ticker Widget for Elementor: from n/a through 1.3.2.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3016 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs News Ticker Widget for Elementor allows Stored XSS.This issue affects News Ticker Widget for Elementor: from n/a through 1.3.2. |
Fixes
Solution
Update the WordPress News Ticker Widget for Elementor wordpress plugin to the latest available version (at least 1.3.3).
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs News Ticker Widget for Elementor allows Stored XSS.This issue affects News Ticker Widget for Elementor: from n/a through 1.3.2. | |
| Title | WordPress News Ticker Widget for Elementor plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-01-10T20:44:09.535Z
Reserved: 2025-01-07T21:05:44.628Z
Link: CVE-2025-22812
No data.
Status : Received
Published: 2025-01-09T16:16:31.047
Modified: 2025-01-09T16:16:31.047
Link: CVE-2025-22812
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD