CVE-2025-48232
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Addons For Beaver Builder – Lite xpro-addons-beaver-builder-elementor allows Stored XSS.This issue affects Xpro Addons For Beaver Builder – Lite: from n/a through <= 1.5.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Xpro Addons For Beaver Builder - Lite (≤1.5.5) allows authenticated attackers to inject malicious scripts into pages viewed by visitors.
Vulnerability
Overview In Xpro Addons For Beaver Builder – Lite versions up to and including 1.5.5, the plugin fails to properly neutralize input during web page generation, leading to a Stored Cross-Site Scripting (XSS) vulnerability [1]. This flaw arises from improper handling of user-supplied data that is later rendered in the browser without adequate sanitization.
Exploitation
Prerequisites The attack requires a privileged user (such as a contributor or higher) to inject malicious script payloads through the Beaver Builder editor interface. Once the crafted content is saved, the payload is stored and executed in the browsers of any user visiting the affected page [1]. No direct user interaction is needed beyond the initial injection by an authenticated user with appropriate permissions.
Impact
Successful exploitation allows an attacker to inject arbitrary JavaScript, HTML, or other script content. This can result in session hijacking, defacement, redirection to malicious sites, or theft of sensitive information when other users, including site visitors, load the compromised page [1].
Mitigation
The vulnerability is addressed in version 1.5.6 of the plugin. Users are advised to update immediately. Auto-update mechanisms for vulnerable plugins can be enabled via Patchstack [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=1.5.5+ 1 more
- (no CPE)range: <=1.5.5
- (no CPE)range: <=1.5.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.