Description
The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2025-07-08
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting in the Calendar and Business Reviews widgets that allows authenticated Contributor+ users to execute arbitrary scripts on other users' browsers
Action: Apply Patch
AI Analysis

Impact

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin contains a stored cross‑site scripting flaw in the Calendar and Business Reviews widgets. Because input from these widgets is not properly sanitized or escaped, an authenticated user with at least Contributor role can insert malicious JavaScript. When a page displaying these widgets is viewed, the injected code runs in the context of the site, potentially allowing cookie theft, session hijacking, or defacement. The vulnerability does not grant arbitrary code execution on the server side, but it compromises the confidentiality and integrity of all site visitors who view the affected content.

Affected Systems

The flaw affects all installations of the Essential Addons plugin up to and including version 6.1.19. Any WordPress site running this plugin with the Calendar or Business Reviews widgets exposed to Contributor or higher roles is vulnerable. The plugin is distributed by wpdevteam and listed in the WordPress plugin repository.

Risk and Exploitability

The CVSS v3 base score of 6.4 classifies the issue as medium severity, while the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack requires the attacker to be authenticated and possess Contributor or higher privileges, and the malicious payload is executed only when a visitor loads a page containing the compromised widget. Because the vulnerability relies on authenticated access and client‑side execution, the overall risk is moderate but still significant for sites that expose these widgets to higher‑privileged users.

Generated by OpenCVE AI on April 22, 2026 at 01:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Essential Addons for Elementor plugin to the latest version available from the vendor.
  • If an update cannot be performed immediately, restrict Contributor and higher roles from editing widget content or revoke those roles from users who do not need them.
  • Disable or remove the Calendar and Business Review widgets from any pages until the plugin is updated, or replace them with alternative safe widgets.

Generated by OpenCVE AI on April 22, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-20374 The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

Wed, 09 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Wpdeveloper
Wpdeveloper essential Addons For Elementor
CPEs cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:*
Vendors & Products Wpdeveloper
Wpdeveloper essential Addons For Elementor

Tue, 08 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 02:30:00 +0000

Type Values Removed Values Added
Description The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wpdeveloper Essential Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:04:24.577Z

Reserved: 2025-06-18T16:15:37.445Z

Link: CVE-2025-6244

cve-icon Vulnrichment

Updated: 2025-07-08T14:28:13.994Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-08T03:15:30.947

Modified: 2025-07-09T13:52:15.010

Link: CVE-2025-6244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T01:15:07Z

Weaknesses