VYPR
Medium severity6.5NVD Advisory· Published Jun 27, 2025· Updated Apr 23, 2026

CVE-2025-53199

CVE-2025-53199

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Slider For Elementor ht-slider-for-elementor allows DOM-Based XSS.This issue affects HT Slider For Elementor: from n/a through <= 1.6.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DOM-Based XSS in HT Slider For Elementor plugin for WordPress (<=1.6.5) allows attackers to inject malicious scripts via crafted input.

Vulnerability

Overview CVE-2025-53199 is a DOM-Based Cross-Site Scripting (XSS) vulnerability found in the HT Slider For Elementor plugin for WordPress, affecting versions up to and including 1.6.5. The root cause is improper neutralization of user input during web page generation, enabling attackers to inject arbitrary scripts into the DOM. This type of flaw is commonly exploited in mass campaigns targeting WordPress sites [1].

Exploitation

Requirements Successful exploitation requires user interaction, such as clicking a malicious link or visiting a crafted page. An attacker must trick a privileged user (e.g., an administrator) into performing an action that triggers the payload. The vulnerability is classified as DOM-Based, meaning the malicious script executes in the victim's browser when the page processes attacker-controlled input [1].

Impact

An attacker can inject scripts that may redirect users to malicious sites, display advertisements, or steal sensitive information. The CVSS v3 score is 6.5 (Medium), indicating potential for significant but not critical harm. However, the vendor notes low severity and low likelihood of exploitation in typical WordPress environments [1].

Mitigation

The vulnerability is patched in version 1.6.6 of HT Slider For Elementor. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. If updating is not possible, consult a hosting provider or web developer for alternative solutions [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.