Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-08-02
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Exclusive Addons for Elementor plugin stores user-supplied input from the exad_infobox_image field without validation or proper output escaping. Authenticated users with Contributor or higher capability can insert arbitrary JavaScript; when the impacted infobox is rendered, the injected code executes in the context of all visitors who view that page, enabling session hijacking, credential theft, or defacement.

Affected Systems

The vulnerability exists in all releases of the Exclusive Addons for Elementor plugin up to and including version 2.7.9.8. Any WordPress site that installs or updates to a version in this range and uses the infobox element exposes the stored exploit.

Risk and Exploitability

With a CVSS score of 6.4 the weakness is considered moderate severity, and the EPSS score of less than 1 percent indicates a low probability of active exploitation in the wild. The attack path requires authenticated access with Contributor or higher capability; once injected, the payload persists until the infobox content is edited. The vulnerability is not listed in the CISA KEV catalog, and the advisories do not mention a patched release, suggesting that newer plugin versions are required for a full fix.

Generated by OpenCVE AI on August 3, 2026 at 09:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Exclusive Addons for Elementor plugin to a version newer than 2.7.9.8 once the vendor releases a patch
  • If an upgrade is not immediately possible, restrict Contributor or higher roles from editing infobox content, or disable the use of the exad_infobox_image parameter until the plugin is updated
  • Configure a web application firewall or content security policy to block common XSS payloads targeting the exad_infobox_image field

Generated by OpenCVE AI on August 3, 2026 at 09:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Timstrifler
Timstrifler exclusive Addons For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Timstrifler
Timstrifler exclusive Addons For Elementor
Wordpress
Wordpress wordpress

Sun, 02 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image'
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Timstrifler Exclusive Addons For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-03T19:53:13.087Z

Reserved: 2026-06-14T22:09:03.060Z

Link: CVE-2026-12231

cve-icon Vulnrichment

Updated: 2026-08-03T19:52:51.359Z

cve-icon NVD

Status : Deferred

Published: 2026-08-02T09:16:33.580

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-12231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T09:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')