Sceawere
Vulnerability Detail
CVE-2026-62078UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Premium Addons Contributor Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Leap13
- Product
- Premium Addons for Elementor
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T13:17:19.053Z",
"pubdate": "2026-09-30T13:17:19.053Z",
"executiveSummary": "The Premium Addons for Elementor plugin, in versions 4.11.105 and below, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability originates from improper input sanitization and output encoding of user-supplied data, specifically within widget parameters accessible to users with the Contributor role or higher.\nSuccessful exploitation allows an authenticated attacker to inject arbitrary malicious JavaScript into the plugin's settings or widget configurations, which is subsequently executed within the browser context of any user viewing the affected page, including administrators.\nThe potential impact includes unauthorized access to administrative sessions, account takeover, exfiltration of sensitive site data, and the delivery of further malicious payloads.\nThe risk is elevated due to the prevalence of the Contributor role in multi-author WordPress environments, where restricted users can achieve elevated privileges through this vector.\nExploitation requires authentication as a user with at least Contributor-level privileges to interact with the plugin's widget settings.",
"technicalDetails": "The vulnerability is identified as a Stored Cross-Site Scripting (XSS) flaw caused by the insufficient sanitization of input fields within Premium Addons for Elementor components. The plugin fails to adequately sanitize or escape data before storing it in the database and subsequently rendering it on the front-end or administrative interface.\nThe root cause lies in the application's handling of widget parameters. Specifically, user-controlled input fields within the Elementor editor are processed without implementing strict 'wp_kses' filters or equivalent output escaping functions (e.g., 'esc_js', 'esc_attr', 'esc_html'). Because the plugin relies on client-side rendering for certain widget elements, these unvalidated inputs are reflected directly into the HTML DOM.\nThe attack flow begins with an attacker authenticated as a Contributor. By accessing the Elementor editor for a post or page, the attacker can insert a malicious payload into vulnerable fields, such as widget titles, custom text areas, or link attributes. When the post is saved, the malicious payload is persisted in the WordPress database.\nUpon visiting the front-end page where the compromised widget is rendered, the server fetches the stored payload and inserts it into the document object model. When the victim's browser parses this content, it executes the embedded JavaScript. Because this execution occurs within the context of the WordPress site, the script can access document cookies (if not protected by HttpOnly flags), perform actions on behalf of the logged-in user via AJAX calls to 'admin-ajax.php', or redirect the victim to an attacker-controlled domain.\nThis vulnerability is particularly impactful because it bypasses the standard restrictions placed on Contributors, who are generally prohibited from performing actions that affect global site security. By leveraging XSS, a Contributor can execute administrative-level functions by triggering actions in the browser of a higher-privileged user who views the manipulated content. There is no requirement for specific network access beyond the standard HTTP/HTTPS channels already established for legitimate WordPress administrative operations. The vulnerability affects all versions up to and including 4.11.105."
}