Description
The PQ Addons – Creative Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on the html_tag parameter in the PQ Section Title widget. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-03-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‐Site Scripting
Action: Patch Immediately
AI Analysis

Impact

The PQ Addons – Creative Elementor Widgets plugin for WordPress allows authenticated users with contributor privileges or higher to submit an invalid html_tag parameter that is stored and later rendered without proper escaping. The stored payload is then executed in the browsers of any user who views the affected page, enabling the attacker to inject arbitrary JavaScript. This can lead to defacement, credential theft, drive‑by installation of malware or hijacking of the current user session. The weakness is a classic stored XSS, classified as CWE‑79.

Affected Systems

The vulnerability exists in all releases up to and including version 1.0.0 of the PQ Addons – Creative Elementor Widgets plugin. Sites that have installed any of those versions, and that provide contributor or higher level access to users, are potentially exposed.

Risk and Exploitability

The CVSS base score of 6.4 indicates a moderate severity, but the requirement of only contributor‑level authentication lowers the practical barrier for exploitation on sites with loose role permissions. No public exploit is currently documented and the vulnerability is not listed in the CISA KEV catalog, yet the lack of input sanitization provides a straightforward attack path. The risk is highest for sites with many contributors or untrusted users, while sites that limit or revoke such permissions can mitigate the threat until a patch is applied.

Generated by OpenCVE AI on March 21, 2026 at 06:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PQ Addons – Creative Elementor Widgets to the latest released version that includes proper input sanitization for the html_tag parameter.
  • If an upgrade is unavailable, remove or delete any Section Title widgets that contain user‑supplied html_tag content.
  • Restrict contributor access or only allow trusted users to edit widgets until the patch is deployed.
  • Verify that no stored XSS payloads remain in the database by reviewing widget content before granting broader access.
  • Keep WordPress and all plugins up to date and monitor the site for anomalous script injections.

Generated by OpenCVE AI on March 21, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Peacefulqode
Peacefulqode pq Addons – Creative Elementor Widgets
Wordpress
Wordpress wordpress
Vendors & Products Peacefulqode
Peacefulqode pq Addons – Creative Elementor Widgets
Wordpress
Wordpress wordpress

Sat, 21 Mar 2026 05:30:00 +0000

Type Values Removed Values Added
Description The PQ Addons – Creative Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on the html_tag parameter in the PQ Section Title widget. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title PQ Addons – Creative Elementor Widgets <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Attributes
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Peacefulqode Pq Addons – Creative Elementor Widgets
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:27:24.751Z

Reserved: 2026-01-23T21:27:49.825Z

Link: CVE-2026-1397

cve-icon Vulnrichment

Updated: 2026-03-24T13:57:46.276Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-21T04:16:53.550

Modified: 2026-03-23T14:32:02.800

Link: CVE-2026-1397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:41:29Z

Weaknesses