CVE-2025-8100: Element Pack Elementor Addons and Templates <= 8.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content
The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'markercontent' parameter in versions up to, and including, 8.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8100?
CVE-2025-8100 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-8100?
To fix CVE-2025-8100, update the Element Pack Elementor Addons and Templates plugin to version 8.1.6 or higher.
What versions are affected by CVE-2025-8100?
Versions of the Element Pack Elementor Addons and Templates plugin up to and including 8.1.5 are affected by CVE-2025-8100.
What is the impact of CVE-2025-8100?
The impact of CVE-2025-8100 includes the potential for attackers to execute malicious scripts on users' browsers through compromised content.
Who is affected by CVE-2025-8100?
Users of the Element Pack Elementor Addons and Templates plugin for WordPress who are on versions 8.1.5 or older are affected by CVE-2025-8100.