CVE-2025-11220: Elementor <= 3.33.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path
The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all versions up to, and including, 3.33.3 due to insufficient neutralization of user-supplied input used to build SVG markup inside the widget. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11220?
The severity of CVE-2025-11220 is considered high due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-11220?
You can fix CVE-2025-11220 by updating the Elementor plugin to version 3.34 or later.
What versions of Elementor are affected by CVE-2025-11220?
CVE-2025-11220 affects all versions of the Elementor plugin up to and including 3.33.3.
What kind of attack does CVE-2025-11220 enable?
CVE-2025-11220 enables Stored Cross-Site Scripting attacks through the Text Path widget.
Who is vulnerable to CVE-2025-11220?
Any WordPress site using the Elementor plugin version 3.33.3 or lower is vulnerable to CVE-2025-11220.