Stored Cross-Site Scripting Vulnerability in King Addons for Elementor Plugin
CVE-2025-7960
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 December 2025
What is CVE-2025-7960?
The King Addons for Elementor plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping on attributes supplied by users. This flaw impacts the Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to and including 51.1.39. Authenticated attackers with contributor-level access and above can exploit this vulnerability to inject arbitrary web scripts into pages, which will execute whenever a user accesses those compromised pages. It's essential for WordPress site owners using this plugin to apply updates and implement security measures to mitigate this risk.
Affected Version(s)
King Addons for Elementor β 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor * <= 51.1.39