Sceawere

Vulnerability Detail

CVE-2026-66688UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ultimate Addons Elementor Contributor XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Brainstorm Force
Product
Ultimate Addons for Elementor
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-06T15:17:22.107Z",
  "pubdate": "2026-08-06T15:17:22.107Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in Ultimate Addons for Elementor versions up to and including 1.45.2. This security flaw enables authenticated users with contributor-level privileges or higher to inject arbitrary web scripts or HTML into the application, which then executes in the context of another user's browser session upon rendering.\nThe impact of this vulnerability includes potential session hijacking, unauthorized access to sensitive application data, defacement, or the execution of unauthorized actions on behalf of victim administrators or other privileged users interacting with the vulnerable plugin components.\nThe affected system is WordPress sites utilizing the specified vulnerable versions of the Ultimate Addons for Elementor plugin. The risk implications are moderate to high depending on the privileges of the victim interacting with the malicious payload. The attacker must possess contributor privileges to successfully store or execute the malicious input within the context of the vulnerable plugin.\nExploitation requires authenticated access with specific low-level posting privileges (such as contributor), allowing the malicious actor to input unsanitized data that is subsequently improperly output by the application interface.",
  "technicalDetails": "The vulnerability is rooted in insufficient input sanitization and output encoding within the Ultimate Addons for Elementor plugin for versions <= 1.45.2. Specifically, parameters supplied by users with contributor-level privileges are processed and stored by the application without proper validation, leading to stored Cross-Site Scripting (XSS) conditions.\nThe vulnerable component involves plugin features and widgets that accept user-supplied configuration data or content fields without adequately sanitizing the input before rendering it back in the Document Object Model (DOM) during administrative or front-end page rendering.\nAttack flow proceeds as follows: First, an authenticated attacker holding a contributor role crafts a malicious payload containing arbitrary JavaScript enclosed within HTML tags or event handlers. Second, the attacker submits this payload via the vulnerable plugin interface or widget settings during content creation or modification. Third, the application stores the unsanitized payload within the database. Fourth, when a higher-privileged user, such as an administrator, views or previews the affected post, page, or plugin settings interface, the stored payload is rendered directly into the victim's browser without adequate context-aware output encoding.\nFinally, the browser executes the injected JavaScript script within the security context of the victim's session, enabling unauthorized actions, theft of sensitive session cookies, or further malicious interactions with the WordPress REST API or administrative backend."
}
CVE-2026-66688: Ultimate Addons Elementor Contributor XSS (MEDIUM Severity, CVSS: 6.5) - Sceawere