Junglewise Threat Intelligence

CVE-2025-14732: Elementor Website Builder Stored XSS in widget parameters

CVE-2025-14732 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Technologies: Elementor Website Builder. Vendors: Elementor.

Executive brief

The Elementor Website Builder plugin for WordPress, a popular tool for designing websites, contains a security flaw that allows users with basic contributor permissions to inject malicious scripts into pages. When other users or administrators visit these affected pages, the scripts execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of site visitors or the theft of sensitive session information.

Technical details

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on several widget parameters. This vulnerability allows authenticated attackers with 'Contributor' level permissions or higher to inject arbitrary web scripts into a page. Because the scripts are stored on the server, they execute in the context of any user's browser who views the compromised page. The issue is present in all versions up to and including 3.35.5. A patch was released in version 3.35.6 to address the improper neutralization of alternate XSS syntax (CWE-87).

Affected products

  • Elementor Elementor Website Builder – More Than Just a Page Builder up to, and including, 3.35.5

Timeline

  • 2026-04-08: advisory: NVD publication date
  • 2026-04-08: disclosed: Wordfence disclosure date
  • 2026-04-08: patched: Version 3.35.6 released to address the issue

References

Related threats