Vulnerability Details CVE-2025-2228
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.8 the 'register_user' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including usernames and passwords of any users who register via the Edit Login | Registration Form widget, as long as that user opens the email notification for successful registration.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.8%
CVSS Severity
CVSS v3 Score 5.7
Products affected by CVE-2025-2228
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:-
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.0.0
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.1.0
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.2.0
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.3.0
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.3.1
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.4.0
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.5.0
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.5.1
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.5.2
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.5.3
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.5.4
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.6.0
-
cpe:2.3:a:cyberchimps:responsive_addons_for_elementor:1.6.1