Sceawere

Vulnerability Detail

CVE-2026-103084UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Premium Addons

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
10h ago
Vendor
LeapWorx
Product
Premium Addons for Elementor
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeapWorx Premium Addons for Elementor premium-addons-for-elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.11.109.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T09:17:06.417Z",
  "pubdate": "2026-10-05T09:17:06.417Z",
  "executiveSummary": "The Premium Addons for Elementor plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.\nThis vulnerability allows an attacker to inject and persist malicious scripts within the affected web application. When a user or administrator views a compromised page containing the injected payload, the script executes within the context of their browser session.\nThe vulnerability affects versions from n/a through 4.11.109 of the Premium Addons for Elementor plugin.\nThe primary risk involves the unauthorized execution of arbitrary JavaScript, which can be leveraged to steal sensitive session cookies, perform unauthorized actions on behalf of the victim, redirect users to malicious domains, or deface the website.\nSuccessful exploitation requires the attacker to have the capability to inject input into the application, which is then rendered unsanitized on the frontend or backend interface.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the affected WordPress environment, as it permits lateral movement or account compromise via administrative session hijacking.",
  "technicalDetails": "The vulnerability originates from a failure to perform adequate input sanitization or output encoding on user-controllable data handled by the Premium Addons for Elementor plugin. Specifically, the plugin processes input that is subsequently rendered in web pages without neutralizing executable characters or scripts.\nRoot Cause Analysis: The application fails to treat user-supplied data as untrusted content, allowing HTML tags and script elements to be stored in the database. When the affected component renders this stored data, the browser interprets the payload as legitimate script code rather than plain text, thereby executing it.\nExploitation Method: An attacker identifies an input field or parameter processed by the plugin that is not correctly sanitized. By submitting a malicious payload—typically containing <script> tags or HTML event handlers such as 'onerror' or 'onload'—the attacker persists the code in the application's database. This payload remains dormant until a victim, such as a site administrator, interacts with the compromised UI component where the data is displayed.\nAttack Flow: 1. The attacker crafts a malicious payload containing an XSS vector. 2. The payload is injected into a vulnerable input field provided by the Premium Addons for Elementor plugin. 3. The plugin saves the input directly to the database without stripping or escaping dangerous characters. 4. The server subsequently retrieves this record to display it to a user. 5. The victim's browser processes the unsanitized input, executing the malicious script within the security context of the victim's session.\nImpact and Payload Behavior: Upon execution, the payload can perform various operations depending on the attacker's intent. Common post-exploitation actions include: 1. Exfiltrating authentication cookies to remote servers to hijack active sessions. 2. Modifying the DOM to display fraudulent content or phishing forms. 3. Initiating unauthorized background requests (CSRF) to change plugin configurations or create new administrative users. 4. Installing keyloggers to capture keystrokes during administrative logins.\nThe scope of this vulnerability covers versions from n/a through 4.11.109. Because the vulnerability involves stored input, the attack is persistent and continues to affect all users who load the compromised elements until the malicious data is manually removed from the underlying database or the code is patched to enforce strict input sanitization/output encoding practices."
}
CVE-2026-103084: Stored XSS in Premium Addons (MEDIUM Severity, CVSS: 6.5) | Sceawere