CVE-2026-8354 Overview
CVE-2026-8354 is a stored Cross-Site Scripting (XSS) vulnerability in the Gum Addon for Elementor plugin for WordPress. The flaw affects all plugin versions up to and including 1.3.15. It exists in the pop_tag parameter of the popover_btn.php widget, which lacks proper input sanitization and output escaping [CWE-79].
Authenticated attackers with contributor-level access or higher can inject arbitrary JavaScript into pages. The injected scripts execute in the browser of any visitor accessing the affected page, enabling session theft, redirection, and privilege escalation chains against site administrators.
Critical Impact
Contributor-level accounts can persist arbitrary JavaScript on public pages, exposing all site visitors and administrators to script execution in their browser context.
Affected Products
- Gum Addon for Elementor plugin for WordPress — versions up to and including 1.3.15
- WordPress sites running the vulnerable plugin with contributor-level or higher user registration
- Elementor-based sites leveraging the Popover Button widget
Discovery Timeline
- 2026-09-19 - CVE-2026-8354 published to the National Vulnerability Database (NVD)
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-8354
Vulnerability Analysis
The vulnerability resides in the popover_btn.php widget of the Gum Addon for Elementor plugin. The pop_tag parameter accepts user-controlled input intended to define an HTML tag but does not enforce an allowlist or escape the value before rendering it into page output.
Because the parameter is stored within the Elementor page data and later reflected during rendering, injected payloads persist across visits. Any authenticated user permitted to edit posts, including the WordPress default contributor role, can supply malicious values.
The scoped impact rating reflects the cross-context nature of XSS: script executes in the browser of end users and administrators, potentially leading to account takeover through cookie theft or forced administrative actions via forged requests.
Root Cause
The root cause is insufficient input validation combined with missing output escaping on the pop_tag widget attribute. The plugin passes attacker-controlled content into the DOM without applying WordPress functions such as esc_attr(), esc_html(), or wp_kses() to neutralize embedded script vectors. Relevant code paths are visible at lines 726 and 767 of widgets/popover_btn.php in the WordPress Plugin Code Repository.
Attack Vector
An attacker with a contributor account edits an Elementor page and configures a Popover Button widget with a crafted pop_tag value containing HTML event handlers or a <script> tag equivalent. Once the page is submitted and later rendered, the payload executes in the browser of every visitor. Full technical details are documented in the Wordfence Vulnerability Report.
The vulnerability manifests when the unsanitized pop_tag value is concatenated into the rendered HTML markup. See the linked plugin source for the exact rendering path.
Detection Methods for CVE-2026-8354
Indicators of Compromise
- Unexpected <script> tags, on* event handlers, or javascript: URIs stored in Elementor page metadata, particularly within Popover Button widget attributes
- New or modified administrator accounts following contributor-level activity on the site
- Outbound browser requests from site visitors to unfamiliar third-party domains loaded from page HTML
Detection Strategies
- Audit the wp_postmeta table for Elementor widget data containing suspicious characters in the pop_tag field such as <, >, ", or on prefixes
- Review site content changes made by contributor and author accounts since the plugin was installed
- Run static scans of rendered page HTML for injected scripts that do not match theme or approved plugin sources
Monitoring Recommendations
- Enable WordPress audit logging to capture post edits, user role changes, and plugin configuration changes
- Monitor web server access logs for POST requests to admin-ajax.php and Elementor editor endpoints originating from low-privilege accounts
- Alert on anomalous JavaScript execution or Content Security Policy (CSP) violations reported by visiting browsers
How to Mitigate CVE-2026-8354
Immediate Actions Required
- Update the Gum Addon for Elementor plugin to a version later than 1.3.15 as soon as the vendor publishes a fix
- Audit all existing pages built with the Popover Button widget for injected payloads in the pop_tag attribute
- Restrict contributor and author account creation and review recent low-privilege registrations
Patch Information
Refer to the WordPress Plugin Changeset Log for the vendor's remediation commit. Administrators should apply the patched release through the WordPress plugin update mechanism and verify the installed version after upgrade.
Workarounds
- Deactivate the Gum Addon for Elementor plugin until a patched release is installed
- Deploy a Web Application Firewall (WAF) rule to block requests containing HTML or script metacharacters in Elementor widget parameters
- Enforce a strict Content Security Policy (CSP) that disallows inline scripts to reduce the impact of stored XSS execution
# Example CSP header to reduce stored XSS impact
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
