Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-07-07
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Exclusive Addons for Elementor plugin contains a stored cross‑site post title is set or modified. The plugin fails to sanitize or escape the title value before storing or rendering it, which allows an attacker to embed arbitrary JavaScript that will execute in the browser of any user who views the affected post. The weakness is classified. The exploited script runs on the client side and can perform, such as modifying page content or capturing information that the browser can access. No server‑side side effects CVE details.

Affected Systems

All installations of Exclusive Addons for Elementor version 2.7.9.8 or earlier, maintained by timstrifler, are affected. The plugin is used within WordPress sites. The vulnerability is only exploitable by users who have Contributor‑level or higher permissions.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. The EPSS score is less than 1 %, suggesting that exploitation is expected to be rare, but a valid account with Contributor access is required for the attack. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by creating or editing a post with a malicious title; the payload who opens that post.

Generated by OpenCVE AI on July 23, 2026 at 14:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Exclusive Addons for Elementor to the latest available version that eliminates the post‑title sanitization issue.
  • If an upgrade cannot be performed immediately, disable the post‑duplicator extension, remove the plugin, or restrict Contributor‑level users from editing post titles until a fix is installed.
  • Ensure that the WordPress theme or a separate plugin performs proper output escaping for post titles additional layer of protection if the plugin remains installed.

Generated by OpenCVE AI on July 23, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Timstrifler
Timstrifler exclusive Addons For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Timstrifler
Timstrifler exclusive Addons For Elementor
Wordpress
Wordpress wordpress

Tue, 07 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Timstrifler Exclusive Addons For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-07T13:42:09.849Z

Reserved: 2026-06-05T06:33:35.761Z

Link: CVE-2026-11328

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T14:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')