CVE-2026-94500

6.5

Roxnor · ElementsKit Elementor addons Lite

A cross-site scripting vulnerability in Roxnor ElementsKit Elementor addons Lite allows authenticated contributors to inject malicious scripts into web pages.

Executive summary

A stored cross-site scripting vulnerability in the ElementsKit Elementor addons Lite plugin for WordPress poses a risk of unauthorized script execution by authenticated contributors.

Vulnerability

This vulnerability is a stored cross-site scripting (CWE-79) flaw. It allows an authenticated user with contributor-level privileges to inject malicious scripts that execute in the context of a victim's browser when they access the affected page.

Business impact

The successful exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript within the session of another user, such as an administrator. This can lead to unauthorized actions, session hijacking, or the theft of sensitive session tokens. Given the CVSS score of 6.5, this is a significant risk for organizations that rely on WordPress for content management, as it undermines the integrity of the administrative interface.

Remediation

Immediate Action: Update the ElementsKit Elementor addons Lite plugin to version 4.0.6 or the latest available version provided by the vendor.

Proactive Monitoring: Monitor WordPress administrative access logs for unusual activity or suspicious script injections originating from contributor-level accounts.

Compensating Controls: Implement a robust Web Application Firewall (WAF) rule to filter or block common XSS payloads directed at the WordPress plugin directory.

Exploitation status

Public Exploit Available: No (exploit_available unknown).

Analyst recommendation

Organizations should prioritize the update of the ElementsKit Elementor addons Lite plugin to version 4.0.6 immediately. Restricting contributor-level access to untrusted users can further reduce the attack surface until the patch is successfully applied across all production environments.

More Roxnor CVEs

History

  1. Analyst report written

Sources

Originally found and disclosed by nh4tvd | Patchstack Bug Bounty Program, per the CVE Program record.