Stored Cross-Site Scripting Vulnerability in All-in-One Addons for Elementor WidgetKit Plugin by WordPress
CVE-2025-8779
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 December 2025
What is CVE-2025-8779?
The All-in-One Addons for Elementor β WidgetKit plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) attacks due to inadequate input sanitization and output escaping on user-supplied attributes within the Team and Countdown widgets. This vulnerability allows authenticated attackers, with contributor-level permissions or higher, to inject malicious web scripts into pages. These scripts are executed whenever a user accesses the compromised page, thereby posing serious security risks to users and site integrity.
Affected Version(s)
All-in-One Addons for Elementor β WidgetKit * <= 2.5.6