Description
The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an attacker to intercept and modify the elementor_ajax AJAX save request in order to bypass the client-side SELECT control restrictions and submit arbitrary tag-name values.
Published: 2026-07-14
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The News Kit Addons for Elementor plugin contains insufficient sanitisation of the Site Logo Title and Single Author Box widgets. This flaw, classified as CWE‑79, allows an authenticated attacker with contributor‑level access or higher to inject arbitrary JavaScript. The injected code is stored in the widget configuration and will execute whenever a user visits a page that renders the modified widget.

Affected Systems

All releases of the News Kit Addons for Elementor plugin from Blazethemes up to and including version 1.4.6 are vulnerable. The issue is specific to WordPress sites that use Elementor and employ the Site Logo Title and Single Author Box widgets.

Risk and Exploitability

The CVSS score of 6.4 indicates medium severity; the EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with contributor privileges who can intercept and modify the elementor_ajax AJAX save request to bypass client in the browsers of any visitor who views the affected widget, making the impact persistent across the site’s audience.

Generated by OpenCVE AI on July 31, 2026 at 10:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the News Kit Addons for Elementor plugin to version 1.4.7 or later as soon as possible.
  • If an immediate upgrade is not feasible, temporarily remove or disable the Site Logo Title and Single Author Box widgets from all public pages until the patch is applied.
  • Limit contributor users to the minimum set of capabilities required for their role, or block their ability to edit widget configurations entirely.

Generated by OpenCVE AI on July 31, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an attacker to intercept and modify the elementor_ajax AJAX save request in order to bypass the client-side SELECT control restrictions and submit arbitrary tag-name values.
Title News Kit Addons For Elementor <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-14T12:31:30.976Z

Reserved: 2026-06-05T15:45:10.434Z

Link: CVE-2026-11390

cve-icon Vulnrichment

Updated: 2026-07-14T12:31:27.811Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')