CVE-2025-13535 Details
Description
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses esc_attr() and esc_url() within JavaScript inline event handlers (onclick attributes), which allows HTML entities to be decoded by the DOM, enabling attackers to break out of the JavaScript context. Additionally, several JavaScript files use unsafe DOM manipulation methods (template literals, .html(), and window.location.href with unvalidated URLs) with user-controlled data. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts via Elementor widget settings that execute when a user accesses the injected page or when an administrator previews the page in Elementor's editor. The vulnerability was partially patched in version 5.1.51.
A series of Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities have been identified in the King Addons for Elementor plugin for WordPress, affecting all versions up to and including 51.1.38. These vulnerabilities arise from inadequate input sanitization and output escaping in various widgets and features. The plugin improperly uses escaping functions within JavaScript inline event handlers, allowing HTML entities to be decoded by the DOM and enabling attackers to escape the JavaScript context. Additionally, several JavaScript files manipulate the DOM unsafely with user-controlled data, creating opportunities for exploitation. Authenticated attackers with Contributor-level access or higher can inject arbitrary scripts via Elementor widget settings, which are executed when a user visits the injected page or when an administrator previews the page in Elementor's editor.
Users can update to King Addons for Elementor version 51.1.51, which includes security enhancements and addresses some of the vulnerabilities.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 1, 2026CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| King Addons for Elementor | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | New CVE Received | [email protected] |
Volerion