Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant Theme Elements for Elementor grandrestaurant-elementor allows Stored XSS.This issue affects Grand Restaurant Theme Elements for Elementor: from n/a through <= 2.1.1.
Published: 2026-01-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Grand Restaurant Theme Elements for Elementor plugin has a stored cross‑site scripting vulnerability. The plugin does not properly neutralize user‑supplied data when generating web pages, which can allow an attacker to save malicious scripts into the site and serve them to any visitor. This allows malicious scripts to run in the browsers of users who view the affected pages.

Affected Systems

The vulnerability affects ThemeGoods’ Grand Restaurant Theme Elements for Elementor plugin as used on WordPress sites. Versions up to and including 2.1.1 are impacted. Any site that has installed the plugin version 2.1.1 or earlier is at risk.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves inserting malicious content via the plugin’s editor or configuration sections that are not filtered before rendering, and requires write access to the site’s theme settings.

Generated by OpenCVE AI on April 29, 2026 at 21:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Grand Restaurant Theme Elements for Elementor to a version newer than 2.1.1.
  • If an upgrade cannot be performed, disable or remove the plugin to eliminate the stored XSS vector.
  • Audit all saved content for embedded scripts, remove any that are not properly escaped and enforce input validation for future content.
  • Restrict untrusted users from accessing the plugin’s editor or configuration settings to limit write abuse.

Generated by OpenCVE AI on April 29, 2026 at 21:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 26 Jan 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Elementor
Elementor elementor
Themegoods
Themegoods grand Restaurant
Wordpress
Wordpress wordpress
Vendors & Products Elementor
Elementor elementor
Themegoods
Themegoods grand Restaurant
Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant Theme Elements for Elementor grandrestaurant-elementor allows Stored XSS.This issue affects Grand Restaurant Theme Elements for Elementor: from n/a through <= 2.1.1.
Title WordPress Grand Restaurant Theme Elements for Elementor plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Elementor Elementor
Themegoods Grand Restaurant
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:08.901Z

Reserved: 2025-10-24T14:25:44.113Z

Link: CVE-2025-63026

cve-icon Vulnrichment

Updated: 2026-01-26T21:56:16.599Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:15:59.790

Modified: 2026-04-27T19:16:18.783

Link: CVE-2025-63026

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T21:45:20Z

Weaknesses