Description
Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions.
Published: 2026-10-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

An unauthenticated Cross Site Scripting vulnerability exists in the WordPress "Blog, Posts and Category Filter for Elementor" plugin versions 2.1.0 and earlier. The flaw allows an attacker to embed malicious JavaScript code via the plugin’s inputs. Once executed, the script runs with the privileges of the page visitor and can steal credentials, deface content, or hijack user sessions. The CWE-79 weakness indicates improper sanitization of user‑supplied data.

Affected Systems

Any WordPress site that has the "Blog, Posts and Category Filter for Elementor" plugin installed at version 2.1.0 or earlier is affected. The plugin, developed by Plugin Devs, is widely used to manage blog posts, pages, and categories through Elementor. No other WordPress core components are directly implicated.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as high severity, reflecting medium to high impact and reasonable ease of exploitation. EPSS data is not available, so the public exploitation likelihood cannot be precisely quantified, but the lack of an authentication requirement and the ability to inject arbitrary scripts elevate the threat. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation at the time of reporting. Attackers would most likely exploit the flaw via a crafted URL or link that includes malicious input processed by the plugin’s filter routines.

Generated by OpenCVE AI on October 6, 2026 at 11:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the "Blog, Posts and Category Filter for Elementor" plugin to the latest released version, which removes the vulnerable code paths.
  • If an immediate upgrade is not possible, disable or delete the plugin to prevent exposure of the vulnerable functionality.
  • Deploy a web application firewall or content security policy that blocks the execution of injected scripts, thus mitigating the effect of any remaining XSS vectors.

Generated by OpenCVE AI on October 6, 2026 at 11:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions.
Title WordPress Blog, Posts and Category Filter for Elementor plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T10:31:32.786Z

Reserved: 2026-04-15T09:21:11.865Z

Link: CVE-2026-40806

cve-icon Vulnrichment

Updated: 2026-10-06T10:29:14.910Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:53.140

Modified: 2026-10-06T11:17:26.973

Link: CVE-2026-40806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T11:15:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')