Description
The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endpoint kit title parameter in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping in an admin attribute context. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-05-27
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Style Kits – Advanced Theme Styles for Elementor plugin allows an authenticated user with contributor-level access or higher to inject arbitrary JavaScript into the kit title field via the "/wp-json/agwp/v1/tokens/save" endpoint. This input is stored and later rendered in an admin attribute context without proper sanitization or escaping, enabling stored cross‑site scripting that will run whenever a user views an injected page. The flaw could be used to deface content, steal session cookies, or hijack user sessions, impacting confidentiality, integrity, and availability of the site.

Affected Systems

WordPress sites that have the analogwp Style Kits for Elementor plugin installed in versions 2.5.0 and earlier.

Risk and Exploitability

The flaw has a CVSS score of 6.4, indicating a moderate severity vulnerability. The EPSS score is not provided, and the issue is not listed in the CISA KEV catalog. The likely attack vector is the authenticated application layer, requiring a user with contributor privileges; the exploit does not require network-level access or elevated OS privileges.

Generated by OpenCVE AI on May 27, 2026 at 03:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Style Kits for Elementor plugin to a version newer than 2.5.0.
  • Limit contributor-level access to trusted personnel or reduce privileges for kit management for untrusted accounts.
  • Implement server‑side input validation and output escaping for the kit title field to prevent XSS.

Generated by OpenCVE AI on May 27, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Analogwp
Analogwp style Kits For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Analogwp
Analogwp style Kits For Elementor
Wordpress
Wordpress wordpress

Wed, 27 May 2026 02:15:00 +0000

Type Values Removed Values Added
Description The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endpoint kit title parameter in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping in an admin attribute context. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Style Kits – Advanced Theme Styles for Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Kit Title
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Analogwp Style Kits For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-27T10:41:52.323Z

Reserved: 2026-04-18T17:29:49.347Z

Link: CVE-2026-6565

cve-icon Vulnrichment

Updated: 2026-05-27T10:41:47.723Z

cve-icon NVD

Status : Received

Published: 2026-05-27T02:16:34.640

Modified: 2026-05-27T02:16:34.640

Link: CVE-2026-6565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T10:08:04Z

Weaknesses