Sceawere

Vulnerability Detail

CVE-2026-62079UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Qi Addons Contributor XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Qode
Product
Qi Addons For Elementor
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T13:17:19.190Z",
  "pubdate": "2026-09-30T13:17:19.190Z",
  "executiveSummary": "The Qi Addons For Elementor plugin, in versions 1.11 and below, contains a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability allows authenticated users with contributor-level permissions to inject malicious scripts into the application.\nBy bypassing existing input sanitization mechanisms, an attacker can execute arbitrary JavaScript in the context of the victim's session, typically an administrator.\nThe impact includes full account takeover, unauthorized modification of website content, and the potential to redirect users or perform actions on behalf of the administrator.\nThis vulnerability is classified as high-risk, as it enables privilege escalation through session hijacking.\nSuccessful exploitation requires the attacker to have at least a contributor-level account on the WordPress installation.\nThe vulnerability highlights the need for robust output encoding and server-side input validation within third-party plugin components.",
  "technicalDetails": "The vulnerability resides in the way Qi Addons For Elementor handles input parameters across various widget settings that are accessible to users with contributor-level privileges. The root cause is the improper sanitization and subsequent insecure output rendering of user-supplied data in the WordPress administrative dashboard.\nWhen a user with contributor privileges edits an Elementor page utilizing Qi Addons, the plugin fails to sufficiently sanitize specific input fields before storing them in the WordPress database. When these unsanitized values are retrieved and rendered within the Elementor editor or the live front-end, the application executes the embedded payload as legitimate HTML and JavaScript.\nThe attack flow proceeds as follows: First, the attacker, logged in as a contributor, accesses the Elementor page builder. Second, the attacker interacts with a vulnerable Qi Addons widget, injecting a malicious payload (e.g., <script>alert(document.cookie)</script>) into a configurable text or attribute field. Third, the plugin saves this payload into the database without applying adequate escaping functions, such as esc_html() or wp_kses_post(). Finally, when an administrator or higher-privileged user opens the affected page in the Elementor editor, the stored script is executed within their browser session.\nThe payload executes with the privileges of the victim's session. Because administrative users have broad permissions, the injected script can be used to perform unauthorized actions such as creating new administrative users, modifying theme files, or exfiltrating session tokens (cookies).\nThe scope of this vulnerability is limited to WordPress installations where the Qi Addons For Elementor plugin (version 1.11 and below) is active. The vulnerability is accessible only to users who already possess sufficient privileges to edit content, meaning it represents a significant escalation of authority for malicious insiders. The exploit does not require remote network access beyond standard authentication to the WordPress back-end, making it a critical threat for sites with multi-user environments that allow untrusted contributors."
}
CVE-2026-62079: Qi Addons Contributor XSS Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere