Description
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-07-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an authenticated user with contributor-level access to inject arbitrary scripts into site pages through the Fancy Text Widget. Because the input is not properly sanitized or escaped, the injected code is stored and executed whenever the affected page is viewed, leading to potential data theft, defacement, or further compromise. The flaw is a classic instance of Stored XSS (CWE‑79).

Affected Systems

The plugin Essential Addons for Elementor – Popular Elementor Templates & Widgets, all releases up to and including version 6.6.11, runs within WordPress sites.

Risk and Exploitability

The CVSS score of 6.4 classifies the flaw as moderate, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not currently listed in CISA's KEV catalog. Attackers would need to log into the WordPress admin interface with contributor‑level or higher privileges, create or edit a page using the Fancy Text Widget, and store malicious script content. Once stored, any visitor to the affected page will execute the injected code. The impact is limited to the scope of the page content but can affect all users who view the page and potentially expose site‑wide secrets if the site’s policy allows scripts to access sensitive information.

Generated by OpenCVE AI on July 30, 2026 at 17:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Essential Addons for Elementor to version 6.7.0 or later, which removes the insecure input handling in the Fancy Text Widget.
  • If an upgrade is not yet possible, delete or disable the Fancy Text Widget from all pages that are publicly accessible, or restrict its use to trusted administrators.
  • Consider tightening contributor role permissions by removing the capability to edit or add shortcodes, or use a role‑management plugin to revoke access to the widget from lower‑privileged users.

Generated by OpenCVE AI on July 30, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam essential Addons For Elementor – Popular Elementor Templates & Widgets
Vendors & Products Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam essential Addons For Elementor – Popular Elementor Templates & Widgets

Tue, 21 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpdevteam Essential Addons For Elementor – Popular Elementor Templates & Widgets
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-23T14:30:37.508Z

Reserved: 2026-07-08T17:29:21.751Z

Link: CVE-2026-15145

cve-icon Vulnrichment

Updated: 2026-07-23T14:30:31.967Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T18:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')