Sceawere

Vulnerability Detail

CVE-2026-96829UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Contributor XSS in The Plus Addons

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
POSIMYTH
Product
The Plus Addons for Elementor Page Builder Lite
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T13:17:32.627Z",
  "pubdate": "2026-09-30T13:17:32.627Z",
  "executiveSummary": "The Plus Addons for Elementor Page Builder Lite, in versions up to and including 6.5.1, contains a vulnerability identified as a Stored Cross-Site Scripting (XSS) flaw.\nThis vulnerability exists due to insufficient sanitization and escaping of user-supplied input within the plugin's widget settings. An authenticated attacker with Contributor-level privileges or higher can inject malicious JavaScript payloads into post or page content.\nUpon rendering by an administrator or another user with higher privileges, the payload executes within the context of the victim's session.\nThe successful exploitation of this vulnerability allows for unauthorized actions on behalf of the victim, such as modifying site content, stealing session cookies, or redirecting users to malicious domains.\nThe risk implication is significant as it facilitates privilege escalation by attacking higher-privileged users, potentially leading to a full compromise of the WordPress installation.\nExploitation requires the attacker to have at least Contributor-level access, meaning the vulnerability is not exploitable by unauthenticated remote actors.",
  "technicalDetails": "The vulnerability originates from inadequate input validation and output encoding within the handling of widget parameters in The Plus Addons for Elementor Page Builder Lite.\nWhen a user with Contributor privileges saves settings for a widget provided by the plugin, the application fails to properly sanitize or escape data stored in specific input fields before saving it to the database.\nThis data is subsequently rendered on the front end or in the Elementor editor interface without appropriate context-aware output encoding (such as esc_html() or esc_attr() in the WordPress context).\nThe attack flow begins when an attacker, possessing at least Contributor permissions, crafts a post or page containing a Plus Addons widget. Within the widget configuration options, the attacker injects an XSS payload, such as a <script> tag or an HTML attribute containing a javascript: URI.\nBecause the plugin does not properly validate this input, the payload is persisted in the database as part of the widget's metadata.\nWhen an administrator or a user with higher privileges (e.g., Editor or Admin) views the page in the editor or the live frontend, the browser interprets the injected payload as legitimate script content, executing it within the victim's authenticated session.\nThe malicious script executes with the privileges of the victim, allowing the attacker to perform actions such as making unauthorized API calls, extracting sensitive session tokens, modifying site configuration, or injecting additional malicious content into the WordPress site.\nThe vulnerability is limited to authenticated users; however, the impact is severe due to the ability to compromise administrative accounts, effectively bypassing the intended privilege separation within the WordPress environment.\nThe scope of this vulnerability affects versions 6.5.1 and below, as these versions fail to implement proper input sanitization techniques on the affected widget input parameters, allowing for the injection of arbitrary malicious code that bypasses the WordPress security model regarding user roles."
}
CVE-2026-96829: Contributor XSS in The Plus Addons (MEDIUM Severity, CVSS: 6.5) | Sceawere