PT-2025-47287 · WordPress+1 · Element Pack Elementor Addons+1

D.Sim

·

Published

2025-11-18

·

Updated

2025-11-18

·

CVE-2025-13196

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Element Pack Addons for Elementor plugin for WordPress versions up to and including 8.3.4
Description The Element Pack Addons for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting through the Open Street Map widget’s marker content parameter. This is a result of inadequate input sanitization and output escaping of user-provided attributes within the render function. Authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will then execute when a user accesses the affected page.
Recommendations Update Element Pack Addons for Elementor plugin for WordPress to a version later than 8.3.4.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-13196

Affected Products

Element Pack Elementor Addons
Elementor