PT-2025-51804 · Elementor+1 · Elementor+1

Craig Smith

·

Published

2025-12-17

·

Updated

2025-12-17

·

CVE-2025-13977

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Essential Addons for Elementor versions up to and including 6.5.3
Description The Essential Addons for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping. Specifically, the issue affects the Event Calendar widget’s custom attributes handling and the Image Masking module’s element ID rendering. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts into pages. These scripts will then execute whenever a user accesses the compromised page.
Recommendations Update Essential Addons for Elementor to a version later than 6.5.3.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-13977

Affected Products

Elementor
Essential Addons For Elementor