CVE-2025-8360 describes a Stored Cross-Site Scripting (XSS) vulnerability in the LA-Studio Element Kit for Elementor WordPress plugin, affecting all versions up to and including 1.5.5.1. This flaw, stemming from insufficient input sanitization, allows authenticated attackers with contributor-level access or higher to inject malicious web scripts into pages. When a user views an affected page, these scripts execute, potentially leading to information disclosure or unauthorized actions. The vulnerability has a CVSS score of 6.4 (Medium), indicating a low attack complexity and requiring local privileges, but with the potential for partial impact on confidentiality and integrity. Despite its medium severity, there is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for CVE-2025-8360 are minimal, with no mentions or articles reported, which is typical for the vast majority of CVEs. The EPSS score is very low, suggesting a low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Choijun | LA-Studio Element Kit For Elementor | >= 0, <= 1.5.5.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.