The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes in the session of any visitor who views the affected content.
History

Fri, 07 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Bdthemes
Bdthemes element Pack Addons For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Bdthemes
Bdthemes element Pack Addons For Elementor
Wordpress
Wordpress wordpress

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes in the session of any visitor who views the affected content.
Title Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-02T06:00:10.952Z

Updated: 2026-08-04T17:42:39.218Z

Reserved: 2026-07-06T08:13:19.524Z

Link: CVE-2026-14817

cve-icon Vulnrichment

Updated: 2026-08-04T17:38:23.619Z

cve-icon NVD

Status : Received

Published: 2026-08-02T06:16:34.793

Modified: 2026-08-04T18:16:43.390

Link: CVE-2026-14817

cve-icon Redhat

No data.