VYPR
Medium severity6.5NVD Advisory· Published May 19, 2025· Updated Apr 28, 2026

CVE-2025-48232

CVE-2025-48232

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Addons For Beaver Builder – Lite xpro-addons-beaver-builder-elementor allows Stored XSS.This issue affects Xpro Addons For Beaver Builder – Lite: from n/a through <= 1.5.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Xpro Addons For Beaver Builder - Lite (≤1.5.5) allows authenticated attackers to inject malicious scripts into pages viewed by visitors.

Vulnerability

Overview In Xpro Addons For Beaver Builder – Lite versions up to and including 1.5.5, the plugin fails to properly neutralize input during web page generation, leading to a Stored Cross-Site Scripting (XSS) vulnerability [1]. This flaw arises from improper handling of user-supplied data that is later rendered in the browser without adequate sanitization.

Exploitation

Prerequisites The attack requires a privileged user (such as a contributor or higher) to inject malicious script payloads through the Beaver Builder editor interface. Once the crafted content is saved, the payload is stored and executed in the browsers of any user visiting the affected page [1]. No direct user interaction is needed beyond the initial injection by an authenticated user with appropriate permissions.

Impact

Successful exploitation allows an attacker to inject arbitrary JavaScript, HTML, or other script content. This can result in session hijacking, defacement, redirection to malicious sites, or theft of sensitive information when other users, including site visitors, load the compromised page [1].

Mitigation

The vulnerability is addressed in version 1.5.6 of the plugin. Users are advised to update immediately. Auto-update mechanisms for vulnerable plugins can be enabled via Patchstack [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.