CVE-2025-13141: HT Mega – Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gutenberg blocks in all versions up to, and including, 3.0.0 due to insufficient input validation on user-supplied HTML tag names. This is due to the lack of a tag name whitelist allowing dangerous tags like 'script', 'iframe', and 'object' to be injected even though tagescape() is used for sanitization. While some blocks use eschtml() for content, this can be bypassed using JavaScript encoding techniques (unquoted strings, backticks, String.fromCharCode()). This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13141?
The severity of CVE-2025-13141 is considered medium due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-13141?
To fix CVE-2025-13141, update the HT Mega – Absolute Addons For Elementor plugin to version 3.0.1 or later, which addresses the input validation issue.
What are the affected versions of the HT Mega – Absolute Addons For Elementor plugin in CVE-2025-13141?
All versions of the HT Mega – Absolute Addons For Elementor plugin up to and including version 3.0.0 are affected by CVE-2025-13141.
What type of vulnerability is CVE-2025-13141?
CVE-2025-13141 is a Stored Cross-Site Scripting vulnerability that allows malicious scripts to be executed within the context of a user's session.
Who is the vendor responsible for CVE-2025-13141?
The vendor responsible for CVE-2025-13141 is HT, the creator of the HT Mega – Absolute Addons For Elementor plugin.