Description
The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Type Out widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-10-03
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to stored cross‑site scripting through the Type Out widget. The vulnerability arises from insufficient input sanitization and output escaping of user‑supplied attributes. An attacker who is authenticated with contributor‑level access or higher can insert arbitrary JavaScript into the widget’s attributes. When a visitor loads a page that contains the compromised widget, the injected script executes in the visitor’s browser.

Affected Systems

Ultra Addons Lite for Elementor plugin for WordPress versions up to and including 1.3.2. WordPress sites operating any of these plugin releases are affected.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. The exploitation requires an authenticated contributor or higher and results in client‑side script execution that can potentially compromise visitor data or interfere with site behavior.

Generated by OpenCVE AI on October 3, 2026 at 06:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ultra Addons Lite for Elementor to version 1.3.3 or later to eliminate unsanitized attribute handling.
  • If an upgrade cannot be performed immediately, disable the Type Out widget on public‑facing pages or remove the plugin until a fixed version is applied.
  • Implement server‑side validation and sanitization for any custom widget attributes, ensuring all output is properly escaped for HTML contexts.

Generated by OpenCVE AI on October 3, 2026 at 06:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Type Out widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Ultra Addons Lite for Elementor <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Type Out Widget
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:44.465Z

Reserved: 2025-11-06T19:20:23.554Z

Link: CVE-2025-12828

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:18.114Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:33.533

Modified: 2026-10-03T16:16:30.267

Link: CVE-2025-12828

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T07:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')