Description
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-07-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an authenticated user with contributor or higher privileges to inject malicious script code through the Reading Progress Global Color Settings feature. Because the input is not sanitized or properly escaped, the injected payload is stored and later delivered to other users when they view pages that use the global color configuration, enabling cross‑site scripting attacks. The impact is execution of arbitrary scripts in the context of site visitors, potentially leading to data theft, session hijacking, or distribution of further malware. This flaw is classified as CWE‑79.

Affected Systems

The issue applies to the Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress in all releases up to and including version 6.6.11. Versions 6.7.0 and later contain the patch that removes the vulnerability.

Risk and Exploitability

The CVSS score of 6.4 indicates a medium‑to‑high severity, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw is not listed in CISA's KEV catalog, reducing immediate threat awareness. Attackers would need authenticated contributor-level access to the WordPress site and would typically use the global color settings panel to persist malicious script code. Once a user opens a page that includes the compromised color setting, the script runs in that user's browser, allowing the attacker to steal session cookies or carry out other client‑side attacks.

Generated by OpenCVE AI on July 30, 2026 at 18:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest plugin release (6.7.0 or newer) to remove the stored XSS flaw.
  • If an immediate upgrade is not possible, temporarily revoke contributor or higher roles from users that do not require editing of global color settings, limiting the ability to inject code.
  • Immediately edit or delete any global color settings that contain unexpected or suspicious HTML or JavaScript payloads and verify that output is properly escaped before rendering to visitors.

Generated by OpenCVE AI on July 30, 2026 at 18:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam essential Addons For Elementor – Popular Elementor Templates & Widgets
Vendors & Products Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam essential Addons For Elementor – Popular Elementor Templates & Widgets

Tue, 21 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpdevteam Essential Addons For Elementor – Popular Elementor Templates & Widgets
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-22T14:19:38.985Z

Reserved: 2026-07-08T19:52:16.601Z

Link: CVE-2026-15156

cve-icon Vulnrichment

Updated: 2026-07-22T14:19:33.449Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T18:15:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')