Stored Cross-Site Scripting Vulnerability in Sky Addons for Elementor Plugin
CVE-2025-8216
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2025
What is CVE-2025-8216?
The Sky Addons for Elementor plugin for WordPress contains a vulnerability that allows for Stored Cross-Site Scripting through multiple widgets. This issue arises from insufficient input sanitization and output escaping in user-supplied attributes. Authenticated attackers with contributor-level access and above can exploit this vulnerability to inject arbitrary web scripts into WordPress pages. When users visit these compromised pages, the injected scripts execute, potentially compromising user data and site integrity.
Affected Version(s)
Sky Addons – Elementor Addons with Widgets & Templates * <= 3.1.4