CVE-2025-7845

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Google Maps and Image Hotspot widgets in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Stratum is a free collection of 20+ <a href="https://motopress.com/products/stratum/" rel="nofollow ugc">widgets for Elementor</a> with the aim of enhancing the existing widget functionality of your favorite page builder. Not only do extras for Elementor by Stratum provide you with highly-customizable elements but also offer automatic adjustment to the visual styling of your current theme.</p> <ul> <li><a href="https://stratum.getmotopress.com/" rel="nofollow ugc">View Demo</a></li> <li><a href="https://motopress.com/blog/category/stratum-elementor-widgets/" rel="nofollow ugc">Stratum widgets</a> overview</li> <li><a href="https://www.facebook.com/groups/stratumaddon" rel="nofollow ugc">Facebook Community</a></li> <li><a href="https://motopress.com/stratum-elementor-widgets-pro-vs-lite/?utm_source=wp-org-stratum-page&amp;utm_medium=text-link&amp;utm_campaign=stratum-pro-table" rel="nofollow ugc">Stratum Free/PRO Comparison Table</a></li> </ul> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/nXFzhxWzxdo?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <h4>WHY STRATUM WIDGETS?</h4> <ul> <li>FREE collection of 20+ business-oriented widgets;</li> <li>Inherits visual styling of your current theme;</li> <li>Does NOT slow down your website;</li> <li>Elementor template library integration;</li> <li>Compatible with other Elementor addons;</li> <li>Fully-adaptive Elementor kit.</li> </ul> <h3>LIST OF FREE WIDGETS FOR ELEMENTOR</h3> <p>Take a look at the entire collection of essential addons for Elementor by Stratum:</p> <ol> <li><a href="https://stratum.getmotopress.com/advanced-accordion/" rel="nofollow ugc">Advanced Accordion</a> &#8211; create interactive content using the horizontal accordion tabs; change the accordion type to toggle; integrate the accordion to your custom Library templates.</li> <li><a href="https://stratum.getmotopress.com/advanced-google-map/" rel="nofollow ugc">Advanced Google Map</a> &#8211; insert your business location on an interactive Google map; use the unlimited number of Google Maps custom markets and map styles.</li> <li><a href="https://stratum.getmotopress.com/advanced-posts/" rel="nofollow ugc">Advanced Posts</a> &#8211; display the latest project news &amp; showcase the automatically sourced posts and pages using various grid, list, carousel, and masonry layouts.</li> <li><a href="https://stratum.getmotopress.com/advanced-slider/" rel="nofollow ugc">Advanced Slider</a> &#8211; display product carousels, intro sliders, to make the user focus on the important message; alter the number of columns, horizontal and vertical scrolling, navigation, etc.</li> <li><a href="https://stratum.getmotopress.com/advanced-tabs/" rel="nofollow ugc">Advanced Tabs</a> &#8211; create fully-customizable horizontal or vertical-oriented tabs that support custom Library templates; shrink the content alignment to space-consuming tabs.</li> <li><a href="https://stratum.getmotopress.com/banner/" rel="nofollow ugc">Banner</a> &#8211; create animated banners for promos and announcements; add dynamics to your WordPress page; promote several offers at once.</li> <li><a href="https://stratum.getmotopress.com/circle-progress-bar/" rel="nofollow ugc">Circle Progress Bar</a> &#8211; display the progress in percentages and/or with a text description.</li> <li><a href="https://stratum.getmotopress.com/counter/" rel="nofollow ugc">Counter</a> &#8211; visualize data using the dynamic animated counter widget.</li> <li><a href="https://stratum.getmotopress.com/flip-box/" rel="nofollow ugc">Flip Box</a> &#8211; make flip boxes with animation with fully customizable front &amp; back sections; choose between 6 flip effects (the same number as the Pro widget).</li> <li><a href="https://stratum.getmotopress.com/image-accordion/" rel="nofollow ugc">Image Accordion</a> &#8211; create compact-style image galleries &amp; banners with multiple-image display; highlight your images with amazing hover and click effects.</li> <li><a href="https://stratum.getmotopress.com/image-hotspot/" rel="nofollow ugc">Image Hotspot</a> &#8211; create animated pointers with tooltips and place them over images; change the styling of pointers &amp; tooltips.</li> <li><a href="https://stratum.getmotopress.com/instagram/" rel="nofollow ugc">Instagram</a> &#8211; implement a real-life Instagram feed to your WordPress website; display any number of posts &amp; change the number of columns; use it as a free PR tool to attract site visitors to follow your business Instagram profile.</li> <li><a href="https://stratum.getmotopress.com/masonry-gallery/" rel="nofollow ugc">Masonry Gallery</a> &#8211; create a stunning gallery display using multiple animation effects.</li> <li><a href="https://stratum.getmotopress.com/price-list/" rel="nofollow ugc">Price List</a> &#8211; create stunning menus, catalogs, and other types of price lists for a website of any kind.</li> <li><a href="https://stratum.getmotopress.com/price-menu/" rel="nofollow ugc">Price Menu</a> &#8211; display food menus or other listings with prices in a beautiful and structured way.</li> <li><a href="https://stratum.getmotopress.com/price-table/" rel="nofollow ugc">Price Table</a> &#8211; let customers compare the pricing for each product/service visually using this widget.</li> <li><a href="https://stratum.getmotopress.com/testimonial-carousel/" rel="nofollow ugc">Testimonial Carousel</a> &#8211; showcase testimonials in the most beautiful &amp; space-consuming way using a carousel; edit reviews in the style that matches your entire website theme.</li> <li><a href="https://stratum.getmotopress.com/vertical-timeline/" rel="nofollow ugc">Vertical Timeline</a> &#8211; display events in a media-rich vertical timeline graph with smooth animation effects.</li> <li><a href="https://stratum.getmotopress.com/horizontal-timeline/" rel="nofollow ugc">Horizontal Timeline</a> &#8211; show events in chronological order using a horizontal timeline framework.</li> <li><a href="https://stratum.getmotopress.com/lottie-animations/" rel="nofollow ugc">Lottie Animations</a> &#8211; add high-quality animations to your WordPress site using the Lottie Animations library and customize animations further.</li> <li><a href="https://stratum.getmotopress.com/countdown/" rel="nofollow ugc">Countdown</a> &#8211; create a circle or box-styled animated countdown timer and set the real-time countdown up to seconds.</li> <li><a href="https://stratum.getmotopress.com/table/" rel="nofollow ugc">Table</a> &#8211; the table widget will allow you to create responsive data tables, style rows and columns.</li> <li><a href="https://stratum.getmotopress.com/content-switcher/" rel="nofollow ugc">Content Switcher</a> &#8211; create tabs or a toggle to structure your content, pricing plans or any other categorized data.</li> </ol> <p>It makes no difference what kind of a business niche you are involved in, nor does it matter whether you develop an Elementor website for yourself or do it as a service. Stratum made both for beginners and pro users to get their best results while styling up content elements for their Elementor websites.</p> <p>Unlike many other third-party Elementor plugins, Stratum offers premium addons for free. Also, the add-on includes several free alternatives to Elementor Pro widgets (Flip Box, Advanced Posts, Testimonial Carousel, etc).</p> <h3>20+ Business-Oriented Elementor Extras</h3> <p>The Stratum&#8217;s widgets for Elementor help you add business-critical content modules to your website built with the Elementor page builder, including animated promo banners, ready-to-go elements for restaurant menus, pricing and comparison tables, and more beautiful content. Elementor plus Stratum means Elementor premium addons without extra charge!</p> <p>All Stratum widgets for Elementor are free, while advanced customization settings are available only in a PRO Stratum version.</p> <p><a href="https://motopress.com/stratum-elementor-widgets-pro-vs-lite/?utm_source=wp-org-stratum-page&amp;utm_medium=text-link&amp;utm_campaign=stratum-pro" rel="nofollow ugc">Check out all the extra features of Stratum</a>.</p> <h3>Ready-To-Go Styling</h3> <p>The unique feature that differs Stratum for Elementor from many other premium third-party addons is the ability of any widget to inherit the styling of the current Elementor theme (typography and colors).</p> <p>The default design set by Stratum addon is able to reduce the time for customizing and adjusting extra widgets to the theme.</p> <h3>Template Library Integration</h3> <p>Integrating custom theme content into Stratum addons means increasing your working efficiency. Stratum stands for fast yet beautiful and advanced editing as in premium add ons.</p> <h3>Build a Mega Menu with Elementor</h3> <p>Want to create a content-rich site navigation menu with Elementor widgets? The Stratum Mega Menu for Elementor addon is the solution &#8211; you can feature your products, posts, banners or whatever content in submenus and fully tweak their styling. Get PRO addons for Elementor for free!</p> <ul> <li><a href="https://motopress.com/products/stratum-menu/?utm_source=wp_org_stratum_page&amp;utm_medium=text_link&amp;utm_campaign=stratum_mega_menu" rel="nofollow ugc">Startum Mega Menu for Elementor Plugin</a></li> <li><a href="https://stratum.getmotopress.com/stratum-mega-menu/?utm_source=wp_org_stratum_page&amp;utm_medium=text_link&amp;utm_campaign=stratum_mega_menu" rel="nofollow ugc">Stratum Mega Menu Demo</a></li> </ul> <h3>About MotoPress</h3> <p>MotoPress is a trusted WordPress developer with over 10 years of experience in creating WordPress tools for content building, including popular <a href="https://motopress.com/products/category/wordpress-booking-plugins/" rel="nofollow ugc">WordPress Booking Plugins</a>.</p> <h3>Copyright</h3> <p>Stratum, Copyright (C) 2020, MotoPress https://motopress.com/<br /> Stratum plugin is distributed under the terms of the GNU GPL.</p> <h3>Credits</h3> <ul> <li>class.settings-api.php, Copyright 2016 Tareq Hasan, MIT license.</li> <li>CountUp.js, Copyright 2019 Jamie Perkins, MIT license.</li> <li>nested.js, Copyright 2013 Andreas Pihlström, MIT license.</li> <li>masonry.pkgd.min.js, Copyright 2016 David DeSandro, MIT license.</li> <li>animOnScroll.js, Copyright 2013 Codrops, MIT license.</li> <li>modernizr.js, Copyright 2014 Faruk, Paul, Alex, Ryan, Patrick, Stu, and Richard, MIT license.</li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
518K