Description
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post.
Published: 2026-07-30
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerable plugin fails to validate the title tag of its Pricing Table widget, which permits users with Contributor or higher roles to embed arbitrary JavaScript. Once the malicious title is stored, the script runs whenever the page is rendered, putting visitors—especially administrators who preview or view the post—at risk of session hijacking or data theft.

Affected Systems

Essential Addons for Elementor for WordPress, versions prior to 6.6.10. Administrators and contributors using sites that have installed these releases are susceptible.

Risk and Exploitability

This flaw carries a CVSS score of 4.8, indicating moderate severity. The EPSS score is below 1%, suggesting low current exploitation probability. It is not listed in the CISA KEV catalog. If a Contributor can create or edit a pricing table, the stored XSS can be triggered by any user who visits the affected page, including site administrators.

Generated by OpenCVE AI on August 3, 2026 at 11:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Essential Addons for Elementor to version 6.6.10 or later.
  • If upgrading is not immediately possible, delete or neutralize any pricing table entries that contain untrusted titles, and remove the widget from inactive or stale posts.
  • Limit Contributor permissions so that only trusted users can edit Pricing Table titles, or enforce input sanitization on the title field to escape embedded tags.

Generated by OpenCVE AI on August 3, 2026 at 11:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam essential Addons For Elementor
Vendors & Products Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam essential Addons For Elementor

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post.
Title Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag
References

Subscriptions

Wordpress Wordpress
Wpdevteam Essential Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-30T12:34:00.047Z

Reserved: 2026-06-25T14:13:28.095Z

Link: CVE-2026-13344

cve-icon Vulnrichment

Updated: 2026-07-30T12:33:54.283Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T06:24:59.293

Modified: 2026-07-30T14:16:31.463

Link: CVE-2026-13344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')