Stored Cross-Site Scripting Vulnerability in Element Pack Addons for Elementor Plugin
CVE-2025-13196

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 November 2025

What is CVE-2025-13196?

The Element Pack Addons for Elementor plugin for WordPress contains a vulnerability that allows authenticated attackers, with contributor-level access or higher, to exploit insufficient input sanitization and output escaping. By manipulating the marker content parameter in the Open Street Map widget, attackers can inject arbitrary web scripts into web pages. These scripts execute when a user accesses the affected page, potentially leading to unauthorized actions or exposure of sensitive information. This vulnerability poses a significant risk to websites utilizing this plugin, particularly those with less stringent access controls.

Affected Version(s)

Element Pack Addons for Elementor * <= 8.3.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D.Sim
.