HomeElementorCVE-2025-3076

CVE-2025-3076

MEDIUM
6.4CVSS
Published: 2025-06-10
Updated: 2025-07-11
AI Analysis

Description

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text’ parameter in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
changed
Confidentiality
low
Integrity
low
Availability
none
Weaknesses
CWE-79

Metadata

Primary Vendor
ELEMENTOR
Published
6/10/2025
Last Modified
7/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

elementor : elementor_page_builder

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-3076 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com