Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.4 WordPress CVE-2026-102394

Stored XSS Vulnerability in Essential Addons for Elementor (CVE-2026-102394)

A stored cross-site scripting vulnerability affects Essential Addons for Elementor through version 6.8.4. The flaw requires low-privileged authentication and user interaction to exploit. No confirmed fixed version is currently available in our fact package.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A stored cross-site scripting (XSS) vulnerability has been disclosed in Essential Addons for Elementor, a WordPress plugin used by over one million sites. Tracked as CVE-2026-102394, the issue allows improper neutralization of input during web page generation, which can result in malicious scripts being stored and executed in the context of the affected site. The vulnerability affects versions through 6.8.4.

What Happened

A stored cross-site scripting vulnerability (CWE-79) was identified in Essential Addons for Elementor, affecting versions through 6.8.4. Stored XSS vulnerabilities allow an attacker to inject malicious script content that is saved by the application and later served to other users, potentially executing in their browsers.

Technical Cause

The vulnerability stems from improper neutralization of input during web page generation, classified under CWE-79 (Cross-site Scripting). According to the CVSS vector, exploitation requires network access, low attack complexity, low-level privileges, and user interaction. The vulnerability affects confidentiality, integrity, and availability at a low impact level each, and the scope is changed, meaning the impact can extend beyond the vulnerable component itself.

Who Is Affected

Sites running Essential Addons for Elementor version 6.8.4 or earlier are affected. The plugin is reported to be installed on over one million WordPress sites, making this a widely relevant issue for site administrators using this plugin.

Affected Versions

The vulnerability affects Essential Addons for Elementor through version 6.8.4. The source data references version 6.8.5 in the plugin's title as a boundary marker, but the fact package does not confirm that 6.8.5 is a released, available fix. Fix availability is explicitly marked as unresolved in our data.

Fixes and Mitigation

Our fact package indicates that a fix is not confirmed as available at this time, despite version 6.8.5 appearing in the advisory title as a reference point. Administrators should monitor the official plugin changelog and update to the latest available version from the WordPress plugin repository as soon as a confirmed fix is released.

Recommended Action

Site administrators using Essential Addons for Elementor should check their currently installed version and monitor official plugin update channels closely. Until a confirmed fixed version is verified, consider restricting access to user roles capable of triggering the stored XSS condition, and review recently submitted content for suspicious script content.

PatchBriefing score

4.4 / 10 · Medium

Official CVSS: 6.5

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Why this score

This vulnerability received a PatchBriefing score of 4.4, reflecting a moderate risk level. The CVSS base score of 6.5 accounts for the largest portion of the score, driven by network-based attack vector and low attack complexity, though exploitation requires low-level privileges and user interaction, which reduces the overall severity. There is no evidence of known exploitation or public exploit code, and EPSS data is not available. The absence of a confirmed fix and the plugin's large installed base (over one million sites) contribute modestly to the score, reflecting both the exposure window and audience reach.

Affected versions

Essential Addons for Elementor < 6.8.5
vulnerable

Reported fixes

Our fact package indicates that a fix is not confirmed as available at this time, despite version 6.8.5 appearing in the advisory title as a reference point. Administrators should monitor the official plugin changelog and update to the latest available version from the WordPress plugin repository as soon as a confirmed fix is released.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
  • NVD (NIST) database
Unified report
Stored XSS Vulnerability in Essential Addons for Elementor (CVE-2026-102394)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email