CVE-2025-5338: Royal Elementor Addons <= 1.7.1028 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1028 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5338?
CVE-2025-5338 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting.
How do I fix CVE-2025-5338?
To fix CVE-2025-5338, update the Royal Elementor Addons plugin to a version later than 1.7.1024.
What impact does CVE-2025-5338 have on websites using Royal Elementor Addons?
CVE-2025-5338 allows attackers to inject malicious scripts into web pages, compromising the security and integrity of affected websites.
Is my site vulnerable if I use an older version of Royal Elementor Addons?
Yes, your site is vulnerable to CVE-2025-5338 if you are running Royal Elementor Addons version 1.7.1024 or below.
Who is affected by CVE-2025-5338?
Any user of the Royal Elementor Addons plugin for WordPress up to version 1.7.1024 is affected by CVE-2025-5338.