Sceawere

Vulnerability Detail

CVE-2026-62078UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Premium Addons Contributor Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Leap13
Product
Premium Addons for Elementor
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T13:17:19.053Z",
  "pubdate": "2026-09-30T13:17:19.053Z",
  "executiveSummary": "The Premium Addons for Elementor plugin, in versions 4.11.105 and below, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability originates from improper input sanitization and output encoding of user-supplied data, specifically within widget parameters accessible to users with the Contributor role or higher.\nSuccessful exploitation allows an authenticated attacker to inject arbitrary malicious JavaScript into the plugin's settings or widget configurations, which is subsequently executed within the browser context of any user viewing the affected page, including administrators.\nThe potential impact includes unauthorized access to administrative sessions, account takeover, exfiltration of sensitive site data, and the delivery of further malicious payloads.\nThe risk is elevated due to the prevalence of the Contributor role in multi-author WordPress environments, where restricted users can achieve elevated privileges through this vector.\nExploitation requires authentication as a user with at least Contributor-level privileges to interact with the plugin's widget settings.",
  "technicalDetails": "The vulnerability is identified as a Stored Cross-Site Scripting (XSS) flaw caused by the insufficient sanitization of input fields within Premium Addons for Elementor components. The plugin fails to adequately sanitize or escape data before storing it in the database and subsequently rendering it on the front-end or administrative interface.\nThe root cause lies in the application's handling of widget parameters. Specifically, user-controlled input fields within the Elementor editor are processed without implementing strict 'wp_kses' filters or equivalent output escaping functions (e.g., 'esc_js', 'esc_attr', 'esc_html'). Because the plugin relies on client-side rendering for certain widget elements, these unvalidated inputs are reflected directly into the HTML DOM.\nThe attack flow begins with an attacker authenticated as a Contributor. By accessing the Elementor editor for a post or page, the attacker can insert a malicious payload into vulnerable fields, such as widget titles, custom text areas, or link attributes. When the post is saved, the malicious payload is persisted in the WordPress database.\nUpon visiting the front-end page where the compromised widget is rendered, the server fetches the stored payload and inserts it into the document object model. When the victim's browser parses this content, it executes the embedded JavaScript. Because this execution occurs within the context of the WordPress site, the script can access document cookies (if not protected by HttpOnly flags), perform actions on behalf of the logged-in user via AJAX calls to 'admin-ajax.php', or redirect the victim to an attacker-controlled domain.\nThis vulnerability is particularly impactful because it bypasses the standard restrictions placed on Contributors, who are generally prohibited from performing actions that affect global site security. By leveraging XSS, a Contributor can execute administrative-level functions by triggering actions in the browser of a higher-privileged user who views the manipulated content. There is no requirement for specific network access beyond the standard HTTP/HTTPS channels already established for legitimate WordPress administrative operations. The vulnerability affects all versions up to and including 4.11.105."
}
CVE-2026-62078: Premium Addons Contributor Stored XSS (MEDIUM Severity, CVSS: 6.5) | Sceawere