Skip to main content
Vulnerability Database/CVE-2026-94168

CVE-2026-94168: Premium Addons for Elementor XSS Flaw

CVE-2026-94168 is a contributor-level cross-site scripting vulnerability in Premium Addons for Elementor affecting versions 4.11.105 and earlier. This article covers technical details, security impact, and mitigation steps.

Published:

CVE-2026-94168 Overview

CVE-2026-94168 is a stored Cross-Site Scripting (XSS) vulnerability in the Premium Addons for Elementor WordPress plugin. The flaw affects all versions up to and including 4.11.105. Attackers with Contributor-level privileges can inject malicious scripts that execute in the browsers of users who view the affected content. The vulnerability is classified under CWE-79 for improper neutralization of input during web page generation.

Critical Impact

Authenticated contributors can inject persistent JavaScript payloads that execute in the context of higher-privileged users, enabling session theft, administrative action abuse, and content manipulation across the WordPress site.

Affected Products

  • Premium Addons for Elementor plugin for WordPress
  • All plugin versions up to and including 4.11.105
  • WordPress sites that grant Contributor or higher roles to untrusted users

Discovery Timeline

  • 2026-09-23 - CVE-2026-94168 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-94168

Vulnerability Analysis

The vulnerability is a stored XSS issue in the Premium Addons for Elementor plugin. The plugin fails to properly sanitize or escape user-supplied input before rendering it back into the page. A user with the Contributor role can embed script content through plugin-provided widgets or attributes. When another user loads the affected page in the Elementor editor or on the frontend, the injected script executes in their browser session.

The attack requires authentication at the Contributor level and user interaction from the victim. However, the scope is changed, meaning the injected script executes in a security context different from the attacker's. This allows the payload to reach administrators or editors who preview or review contributor-submitted content.

Root Cause

The root cause is improper neutralization of input during web page generation [CWE-79]. The plugin accepts input from contributor-level users through Elementor widget parameters and outputs that data into HTML without applying context-appropriate escaping. WordPress core normally strips unsafe HTML from Contributor input, but plugin-specific fields can bypass this filtering when the plugin renders raw values.

Attack Vector

An authenticated attacker with a Contributor account crafts a post or page using a vulnerable Premium Addons for Elementor widget. The attacker supplies a JavaScript payload in a widget field that the plugin renders without escaping. The malicious content persists in the WordPress database. When an editor or administrator previews the draft or an unauthenticated visitor loads the published page, the script runs in their browser.

Refer to the Patchstack XSS Vulnerability Advisory for additional technical detail.

Detection Methods for CVE-2026-94168

Indicators of Compromise

  • Unexpected <script> tags, on* event handlers, or javascript: URIs stored in WordPress postmeta or posts tables
  • Draft or pending posts authored by Contributor accounts that include Premium Addons for Elementor widget markup with unusual attribute values
  • Administrator or editor sessions that generate outbound requests to unfamiliar domains shortly after previewing contributor content
  • New administrator accounts, changed passwords, or altered site options following contributor content review

Detection Strategies

  • Audit WordPress post content and meta for HTML event handlers and inline scripts introduced by non-administrator authors
  • Enable WordPress activity logging to correlate contributor edits with subsequent privileged session activity
  • Deploy a web application firewall rule set that flags XSS payload patterns submitted to admin-ajax.php and Elementor editor endpoints
  • Compare installed plugin versions against the fixed release across your WordPress fleet

Monitoring Recommendations

  • Monitor browser Content Security Policy (CSP) violation reports for inline script execution on WordPress admin and preview URLs
  • Alert on privileged user sessions that trigger outbound requests to attacker-controlled endpoints during content review workflows
  • Track plugin update status and identify sites still running Premium Addons for Elementor 4.11.105 or earlier

How to Mitigate CVE-2026-94168

Immediate Actions Required

  • Update Premium Addons for Elementor to the version identified as fixed in the Patchstack advisory
  • Review all Contributor and Author accounts and remove any that are not required
  • Inspect drafts and pending posts for injected script content before administrators preview them
  • Rotate credentials for any administrator who previewed suspicious contributor content

Patch Information

Upgrade Premium Addons for Elementor beyond version 4.11.105. Consult the Patchstack XSS Vulnerability Advisory for the specific patched release and vendor guidance.

Workarounds

  • Restrict the Contributor role or replace it with a custom role that cannot access Premium Addons for Elementor widgets until the patch is applied
  • Enforce a strict Content Security Policy that blocks inline scripts on WordPress editor and preview routes
  • Deploy a web application firewall signature that blocks XSS payloads targeting Elementor widget parameters
  • Temporarily deactivate the Premium Addons for Elementor plugin on sites where Contributor accounts are actively used
bash
# Configuration example: check installed plugin version via WP-CLI
wp plugin get premium-addons-for-elementor --field=version
wp plugin update premium-addons-for-elementor

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.