Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.3.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a DOM‑Based Cross‑Site Scripting (XSS) flaw in the ElementInvader Addons for Elementor plugin. Unsanitized user input is included in generated HTML, allowing an attacker to inject and execute arbitrary JavaScript in the context of the site. This can lead to cookie theft, session hijacking, defacement or delivery of additional malware to visitors. The flaw does not provide remote code execution but affects the confidentiality and integrity of users who interact with the affected pages.

Affected Systems

The flaw affects the ElementInvader:ElementInvader Addons for Elementor plugin, version 1.4.3 and earlier. WordPress sites that have installed any of these versions and use the plugin are impacted; the impact occurs entirely in the client browsers.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is considered high severity, the EPSS score indicates a low exploitation probability (< 1%), and the KEV status is not listed. It triggers the XSS when the page loads, potentially affecting any affected component. The attack vector is client‑side and does not require privileged access to the server. Because the flaw is DOM‑based, exploitation is limited to the browser environment, but it can still be highly damaging to user data and the site’s reputation.

Generated by OpenCVE AI on July 31, 2026 at 12:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ElementInvader Addons version that contains the XSS fix; if version 1.4.4 or newer is not yet available, wait until the developer releases a patched build.
  • If an upgrade cannot be performed immediately, disable or remove the plugin from the WordPress installation to eliminate the vulnerability.
  • Deploy a site‑wide Content Security Policy that blocks inline script execution and limits script sources to trusted origins, reducing the effect of any remaining or future XSS vectors.

Generated by OpenCVE AI on July 31, 2026 at 12:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Elementinvader
Elementinvader elementinvader Addons For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Elementinvader
Elementinvader elementinvader Addons For Elementor
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.3.
Title WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Elementinvader Elementinvader Addons For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:54.325Z

Reserved: 2026-06-24T12:45:54.515Z

Link: CVE-2026-57376

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')