Pencilwp develops WordPress plugin extensions, specifically add-ons for the widely used Elementor page builder platform, where the vulnerability profile centers on input-handling weaknesses in web-facing form and content generation. The durable signal reflects the exposure inherent to user-input processing in WordPress plugins; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pencilwp over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48132MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor x-addons-elementor allows Stored XSS.This issu | May 16, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pencilwp.
Media articles that mention a CVE ID that affects a product developed by Pencilwp — matched by CVE ID, not by vendor name.