CVE-2025-1054Patch

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the UI Counter, UI Icon Box, UI Testimonial Slider, UI Testimonial Grid, and UI Testimonial Carousel widgets in all versions up to, and including, 1.0.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-09: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-09: 102-09
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • AdScriptly.io@AdscriptlyIo
    Patch

    PostgreSQL acaba de publicar su tercer CVE crítico en 10 años. Si usas cualquier versión desde la 12, estás afectado. El ataque permite robar datos sin autenticación, y los parches ya están disponibles para aplicar sin downtime. https://www.adscriptly.io/es/news/postgresql-17-2-cve-2025-1054-critical-patch-2026

    Post summary

    PostgreSQL has announced its third critical CVE in a decade; versions 12 and newer are vulnerable to unauthenticated data theft, but patches are already available and can be applied with no downtime.

    0000038
    4 followersView on X

Explore more