Medium · 4.4 WordPress CVE-2026-102394
Stored XSS Vulnerability in Essential Addons for Elementor (CVE-2026-102394)
A stored cross-site scripting vulnerability affects Essential Addons for Elementor through version 6.8.4. The flaw requires low-privileged authentication and user interaction to exploit. No confirmed fixed version is currently available in our fact package.
AI summary
A stored cross-site scripting (XSS) vulnerability has been disclosed in Essential Addons for Elementor, a WordPress plugin used by over one million sites. Tracked as CVE-2026-102394, the issue allows improper neutralization of input during web page generation, which can result in malicious scripts being stored and executed in the context of the affected site. The vulnerability affects versions through 6.8.4.
What Happened
A stored cross-site scripting vulnerability (CWE-79) was identified in Essential Addons for Elementor, affecting versions through 6.8.4. Stored XSS vulnerabilities allow an attacker to inject malicious script content that is saved by the application and later served to other users, potentially executing in their browsers.
Technical Cause
The vulnerability stems from improper neutralization of input during web page generation, classified under CWE-79 (Cross-site Scripting). According to the CVSS vector, exploitation requires network access, low attack complexity, low-level privileges, and user interaction. The vulnerability affects confidentiality, integrity, and availability at a low impact level each, and the scope is changed, meaning the impact can extend beyond the vulnerable component itself.
Who Is Affected
Sites running Essential Addons for Elementor version 6.8.4 or earlier are affected. The plugin is reported to be installed on over one million WordPress sites, making this a widely relevant issue for site administrators using this plugin.
Affected Versions
The vulnerability affects Essential Addons for Elementor through version 6.8.4. The source data references version 6.8.5 in the plugin's title as a boundary marker, but the fact package does not confirm that 6.8.5 is a released, available fix. Fix availability is explicitly marked as unresolved in our data.
Fixes and Mitigation
Our fact package indicates that a fix is not confirmed as available at this time, despite version 6.8.5 appearing in the advisory title as a reference point. Administrators should monitor the official plugin changelog and update to the latest available version from the WordPress plugin repository as soon as a confirmed fix is released.
Recommended Action
Site administrators using Essential Addons for Elementor should check their currently installed version and monitor official plugin update channels closely. Until a confirmed fixed version is verified, consider restricting access to user roles capable of triggering the stored XSS condition, and review recently submitted content for suspicious script content.
PatchBriefing score
4.4 / 10 · Medium
Official CVSS: 6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Why this score
This vulnerability received a PatchBriefing score of 4.4, reflecting a moderate risk level. The CVSS base score of 6.5 accounts for the largest portion of the score, driven by network-based attack vector and low attack complexity, though exploitation requires low-level privileges and user interaction, which reduces the overall severity. There is no evidence of known exploitation or public exploit code, and EPSS data is not available. The absence of a confirmed fix and the plugin's large installed base (over one million sites) contribute modestly to the score, reflecting both the exposure window and audience reach.
Affected versions
- Essential Addons for Elementor < 6.8.5
- vulnerable
Reported fixes
Our fact package indicates that a fix is not confirmed as available at this time, despite version 6.8.5 appearing in the advisory title as a reference point. Administrators should monitor the official plugin changelog and update to the latest available version from the WordPress plugin repository as soon as a confirmed fix is released.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
WPVulnerability database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email