CVE-2025-13535
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses esc_attr() and esc_url() within JavaScript inline event handlers (onclick attributes), which allows HTML entities to be decoded by the DOM, enabling attackers to break out of the JavaScript context.
Leer descripción completaMostrar menos
Additionally, several JavaScript files use unsafe DOM manipulation methods (template literals, .html(), and window.location.href with unvalidated URLs) with user-controlled data. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts via Elementor widget settings that execute when a user accesses the injected page or when an administrator previews the page in Elementor's editor. The vulnerability was partially patched in version 5.1.51.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Puntuación base: 6.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.24%
- Percentil entre todas las CVEs puntuadas: 14
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-79
Referencias
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/assets/libraries/lightgallery/lightgallery.js
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/features/Wrapper_Link/Wrapper_Link.php#L85
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Countdown/script.js#L119
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Image_Accordion/script.js#L141
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Off_Canvas_Content/Off_Canvas_Content.php#L629
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Popup/Popup.php#L708
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Pricing_Calculator/Pricing_Calculator.php#L1896
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Video_Popup/Video_Popup.php#L813
- https://plugins.trac.wordpress.org/changeset/3438067/
- https://plugins.trac.wordpress.org/changeset/3441952/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/95d3e76c-612d-436c-9d32-6228d7dcbf35?source=cve
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-13535",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-13535",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-04-01T19:03:46.391810Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "security@wordfence.com",
"affectedData": [
{
"vendor": "kingaddons",
"product": "King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "51.1.53"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-04-01T15:16:21.743",
"references": [
{
"url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/assets/libraries/lightgallery/lightgallery.js",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/features/Wrapper_Link/Wrapper_Link.php#L85",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Countdown/script.js#L119",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Image_Accordion/script.js#L141",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Off_Canvas_Content/Off_Canvas_Content.php#L629",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Popup/Popup.php#L708",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Pricing_Calculator/Pricing_Calculator.php#L1896",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Video_Popup/Video_Popup.php#L813",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3438067/",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3441952/",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/95d3e76c-612d-436c-9d32-6228d7dcbf35?source=cve",
"source": "security@wordfence.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses esc_attr() and esc_url() within JavaScript inline event handlers (onclick attributes), which allows HTML entities to be decoded by the DOM, enabling attackers to break out of the JavaScript context. Additionally, several JavaScript files use unsafe DOM manipulation methods (template literals, .html(), and window.location.href with unvalidated URLs) with user-controlled data. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts via Elementor widget settings that execute when a user accesses the injected page or when an administrator previews the page in Elementor's editor. The vulnerability was partially patched in version 5.1.51."
},
{
"lang": "es",
"value": "El plugin King Addons for Elementor para WordPress es vulnerable a múltiples vulnerabilidades de cross-site scripting almacenado basado en DOM de Contributor+ en todas las versiones hasta, e incluyendo, la 51.1.38. Esto se debe a una sanitización de entrada insuficiente y un escape de salida en múltiples widgets y características. El plugin utiliza esc_attr() y esc_url() dentro de manejadores de eventos en línea de JavaScript (atributos onclick), lo que permite que las entidades HTML sean decodificadas por el DOM, permitiendo a los atacantes salir del contexto de JavaScript. Además, varios archivos JavaScript utilizan métodos de manipulación del DOM inseguros (literales de plantilla, .html(), y window.location.href con URLs no validadas) con datos controlados por el usuario. Esto hace posible que atacantes autenticados, con acceso de nivel Contributor y superior, inyecten scripts web arbitrarios a través de la configuración de widgets de Elementor que se ejecutan cuando un usuario accede a la página inyectada o cuando un administrador previsualiza la página en el editor de Elementor. La vulnerabilidad fue parcialmente parcheada en la versión 5.1.51."
}
],
"lastModified": "2026-09-30T23:10:00.237",
"sourceIdentifier": "security@wordfence.com"
}