PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-13535 kingaddons CVE debrief

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses esc_attr() and esc_url() within JavaScript inline event handlers (onclick attributes), which allows HTML entities to be decoded by the DOM, enabling attackers to break out of the JavaScript context. Additionally, several JavaScript files use unsafe DOM manipulation methods (template literals, .html(), and window.location.href with unvalidated URLs) with user-controlled data.

Vendor
kingaddons
Product
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-01
Original CVE updated
2026-09-30
Advisory published
2026-04-01
Advisory updated
2026-09-30

Who should care

Defenders responsible for WordPress installations using the King Addons for Elementor plugin, especially those with Contributor-level access or above, should assess exposure and verify the effectiveness of current input sanitization and output escaping measures.

Why it matters

The King Addons for Elementor plugin vulnerability allows authenticated attackers to inject arbitrary web scripts, potentially leading to security breaches and data compromise.

  • Verify exposure of WordPress installations to DOM-Based Stored Cross-Site Scripting attacks
  • Assess the effectiveness of current input sanitization and output escaping measures
  • Enhance security measures for multiple widgets and features in the King Addons for Elementor plugin
  • Prioritize upgrading to a patched version of the plugin, if available

Technical summary

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities due to insufficient input sanitization and output escaping across multiple widgets and features. This allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via Elementor widget settings. The vulnerability uses esc_attr() and esc_url() within JavaScript inline event handlers (onclick attributes), which allows HTML entities to be decoded by the DOM, enabling attackers to break out of the JavaScript context.

Defensive priority

Defenders should prioritize verifying exposure of WordPress installations using the King Addons for Elementor plugin, especially those with Contributor-level access or above, and assess the effectiveness of current input sanitization and output escaping measures.

Recommended defensive actions

  • Verify WordPress installations for the King Addons for Elementor plugin version 51.1.38 or earlier
  • Assess user roles and access levels to identify potential Contributor-level access or above
  • Review and enhance input sanitization and output escaping measures for multiple widgets and features
  • Consider upgrading to a patched version of the plugin, if available
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and vector. Multiple source references from Wordfence provide additional context and specific code examples.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-13535 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-13535

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-13535 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-13535

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/assets/libraries/lightgallery/lightgallery.js

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/features/Wrapper_Link/Wrapper_Link.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Countdown/script.js

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Image_Accordion/script.js

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Off_Canvas_Content/Off_Canvas_Content.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Popup/Popup.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Pricing_Calculator/Pricing_Calculator.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.38/includes/widgets/Video_Popup/Video_Popup.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.