CVE-2025-13997Disclosure

LOWCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all versions up to, and including, 51.1.49 due to the plugin adding the API keys to the HTML source code via render_full_form function. This makes it possible for unauthenticated attackers to extract site's Mailchimp, Facebook and Google API keys and secrets. This vulnerability requires the Premium license to be installed

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-23: 3Active Exploitation · 2026-03-23: 1Technical Details · 2026-03-23: 103-23
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting kingaddons King Addons for Elementor Plugin (CVE-2025-13997) https://vuldb.com/?ctiid.352496

    Post summary

    Active exploitation of CVE-2025-13997 targeting the King Addons for Elementor Plugin has been identified.

    00000115
    2.1K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-13997 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-13997 #CVE-2025-13997 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/bmFNfWnLlT

    Post summary

    The tweet announces CVE‑2025‑13997, a Medium‑severity vulnerability affecting WordPress, but offers only basic severity details without any exploit or patch information.

    0000065
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13997 The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated … https://www.cve.org/CVERecord?id=CVE-2025-13997

    Post summary

    The text announces a new CVE (CVE-2025-13997) for The King Addons for Elementor plugin, noting an unauthenticated vulnerability but providing no further technical details, PoC, or mitigation information.

    0000056
    56.8K followersView on X

Explore more