CVE-2025-13535Disclosure

LOWCVSS 6.4 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses esc_attr() and esc_url() within JavaScript inline event handlers (onclick attributes), which allows HTML entities to be decoded by the DOM, enabling attackers to break out of the JavaScript context. Additionally, several JavaScript files use unsafe DOM manipulation methods (template literals, .html(), and window.location.href with unvalidated URLs) with user-controlled data. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts via Elementor widget settings that execute when a user accesses the injected page or when an administrator previews the page in Elementor's editor. The vulnerability was partially patched in version 5.1.51.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-01: 3PoC Mentioned / Linked · 2026-04-01: 1Technical Details · 2026-04-01: 204-01
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2025-13535-king-addons-version-51-1-53-medium-vulnerability-proof-of-concept CVE-2025-13535 #WordPress plugin #vulnerability king-addons#cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A tweet links to a proof‑of‑concept page for CVE‑2025‑13535 affecting the King Addons WordPress plugin, but provides no additional exploit, patch, or technical details.

    00000181
    5 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13535 The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to,… https://www.cve.org/CVERecord?id=CVE-2025-13535

    Post summary

    The text announces that the King Addons for Elementor plugin is affected by multiple DOM‑based stored XSS vulnerabilities (CVE‑2025‑13535) but provides no evidence of exploitation, patches, or false reporting.

    00000111
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-13535 - King Addons for Elementor <= 51.1.38 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Widgets Intel Report: https://ift.tt/NPtX7EU

    Post summary

    An alert announcing CVE‑2025‑13535, a DOM‑based stored XSS in King Addons for Elementor (≤ 51.1.38) that requires Contributor+ authentication, with no evidence of active exploitation or a PoC.

    00000199
    281 followersView on X

Explore more