CVE-2026-94168

6.5

Leap13 · Premium Addons for Elementor

A stored cross-site scripting vulnerability in the Premium Addons for Elementor plugin allows authenticated contributors to inject malicious scripts into web pages.

Executive summary

The Premium Addons for Elementor plugin contains a cross-site scripting vulnerability that could allow authenticated contributors to execute arbitrary scripts in the context of other users.

Vulnerability

This is a stored cross-site scripting (XSS) vulnerability (CWE-79) triggered by insufficient input neutralization. It requires an attacker to have at least Contributor-level privileges to inject malicious scripts into the application.

Business impact

Successful exploitation allows an attacker to execute arbitrary scripts in the browser of other users, including administrators. This can lead to session hijacking, unauthorized actions performed on behalf of legitimate users, or the redirection of traffic to malicious sites. While the CVSS score is 6.5, the potential for privilege escalation within the WordPress environment poses a significant risk to site integrity and user data confidentiality.

Remediation

Immediate Action: Update the Premium Addons for Elementor plugin to version 4.11.106 or the latest available version provided by Leap13.

Proactive Monitoring: Review administrative and contributor account activity logs for suspicious post updates or unusual script injection patterns within page content.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block common XSS injection patterns.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for unauthorized script execution, administrators should prioritize updating the affected plugin immediately. Failure to patch the software leaves the site vulnerable to cross-site scripting attacks that could compromise administrative sessions and site integrity.

More Leap13 CVEs

History

  1. Analyst report written

Sources

Originally found and disclosed by Intrudify | Patchstack Bug Bounty Program, per the CVE Program record.