Description
Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting enabling arbitrary client‑side script injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a Cross Site Scripting flaw that allows an attacker to inject malicious client‑side scripts through the Element Pack Elementor Addons plugin when a user with content editing privileges submits specially crafted input. This defect is a classic input validation failure identified as CWE‑79. The injection can execute in the browsers of any visitor to the WordPress site, potentially leading to defacement, cookie theft, or phishing attacks. The potential consequences are limited to the affected site’s confidentiality, integrity, and availability, but there is no remote code execution or system compromise beyond the web application context.

Affected Systems

This defect affects the bdthemes Element Pack Elementor Addons plugin for WordPress, versions 8.8.3 and earlier. The published fix begins in version 8.8.4, which removes the vulnerable input handling. Site administrators should verify the plugin’s version and apply the latest update to prevent exploitation.

Risk and Exploitability

The CVSS score of 6.5 signals a medium‑severity risk. EPSS is not currently available, and the issue does not appear in the CISA KEV catalog, suggesting limited known exploitation. Based on the description, it is inferred that the attacker would need to use the plugin’s authoring interface or possess a privileged user role to insert malicious content, after which any site visitor will run the script.

Generated by OpenCVE AI on September 17, 2026 at 22:28 UTC.

Remediation

Vendor Solution

Update the WordPress Element Pack Elementor Addons Plugin to the latest available version (at least 8.8.4).


OpenCVE Recommended Actions

  • Update the Element Pack Elementor Addons plugin to version 8.8.4 or later to remove the vulnerable code paths.
  • Audit all existing site content for injected scripts or suspicious HTML and remove them.
  • Deploy a Content Security Policy that disallows inline scripts and restricts allowed script sources to reduce the impact of any residual XSS vectors.

Generated by OpenCVE AI on September 17, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Bdthemes
Bdthemes element Pack Elementor Addons
Wordpress
Wordpress wordpress
Vendors & Products Bdthemes
Bdthemes element Pack Elementor Addons
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
Title WordPress Element Pack Elementor Addons plugin <= 8.8.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Bdthemes Element Pack Elementor Addons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T02:21:38.543Z

Reserved: 2026-07-27T13:59:59.780Z

Link: CVE-2026-66574

cve-icon Vulnrichment

Updated: 2026-09-19T02:21:34.298Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:15.953

Modified: 2026-09-19T03:17:14.793

Link: CVE-2026-66574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')