PatchSiren cyber security CVE debrief
CVE-2025-13535 kingaddons CVE debrief
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses esc_attr() and esc_url() within JavaScript inline event handlers (onclick attributes), which allows HTML entities to be decoded by the DOM, enabling attackers to break out of the JavaScript context. Additionally, several JavaScript files use unsafe DOM manipulation methods (template literals, .html(), and window.location.href with unvalidated URLs) with user-controlled data.
- Vendor
- kingaddons
- Product
- King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-01
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-04-01
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for WordPress installations using the King Addons for Elementor plugin, especially those with Contributor-level access or above, should assess exposure and verify the effectiveness of current input sanitization and output escaping measures.
Why it matters
The King Addons for Elementor plugin vulnerability allows authenticated attackers to inject arbitrary web scripts, potentially leading to security breaches and data compromise.
- Verify exposure of WordPress installations to DOM-Based Stored Cross-Site Scripting attacks
- Assess the effectiveness of current input sanitization and output escaping measures
- Enhance security measures for multiple widgets and features in the King Addons for Elementor plugin
- Prioritize upgrading to a patched version of the plugin, if available
Technical summary
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities due to insufficient input sanitization and output escaping across multiple widgets and features. This allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via Elementor widget settings. The vulnerability uses esc_attr() and esc_url() within JavaScript inline event handlers (onclick attributes), which allows HTML entities to be decoded by the DOM, enabling attackers to break out of the JavaScript context.
Defensive priority
Defenders should prioritize verifying exposure of WordPress installations using the King Addons for Elementor plugin, especially those with Contributor-level access or above, and assess the effectiveness of current input sanitization and output escaping measures.
Recommended defensive actions
- Verify WordPress installations for the King Addons for Elementor plugin version 51.1.38 or earlier
- Assess user roles and access levels to identify potential Contributor-level access or above
- Review and enhance input sanitization and output escaping measures for multiple widgets and features
- Consider upgrading to a patched version of the plugin, if available
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and vector. Multiple source references from Wordfence provide additional context and specific code examples.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-13535 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-13535
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-13535 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-13535
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/assets/libraries/lightgallery/lightgallery.js
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/features/Wrapper_Link/Wrapper_Link.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Countdown/script.js
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Image_Accordion/script.js
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Off_Canvas_Content/Off_Canvas_Content.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Popup/Popup.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Pricing_Calculator/Pricing_Calculator.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Video_Popup/Video_Popup.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.