CVE-2025-3076: Elementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘buttontext’ parameter in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3076?
CVE-2025-3076 has been rated as a high severity vulnerability due to its potential for exploiting stored cross-site scripting.
How do I fix CVE-2025-3076?
To fix CVE-2025-3076, update the Elementor Website Builder Pro plugin to version 3.29.1 or later.
Who is affected by CVE-2025-3076?
CVE-2025-3076 affects all versions of the Elementor Website Builder Pro plugin for WordPress up to and including 3.29.0.
What type of attack does CVE-2025-3076 facilitate?
CVE-2025-3076 facilitates stored cross-site scripting attacks via the ‘button_text’ parameter due to insufficient input sanitization.
What are the implications of CVE-2025-3076 for website security?
CVE-2025-3076 can allow authenticated attackers to inject malicious scripts into web pages, potentially compromising user data and website integrity.