Stored Cross-Site Scripting Vulnerability in King Addons for Elementor Plugin
CVE-2025-7960

6.4MEDIUM

What is CVE-2025-7960?

The King Addons for Elementor plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping on attributes supplied by users. This flaw impacts the Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to and including 51.1.39. Authenticated attackers with contributor-level access and above can exploit this vulnerability to inject arbitrary web scripts into pages, which will execute whenever a user accesses those compromised pages. It's essential for WordPress site owners using this plugin to apply updates and implement security measures to mitigate this risk.

Affected Version(s)

King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor * <= 51.1.39

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D.Sim
.
CVE-2025-7960 : Stored Cross-Site Scripting Vulnerability in King Addons for Elementor Plugin