Executive brief
The Elementor Website Builder plugin for WordPress, a popular tool for designing websites, contains a security flaw that allows users with basic contributor permissions to inject malicious scripts into pages. When other users or administrators visit these affected pages, the scripts execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of site visitors or the theft of sensitive session information.
Technical details
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on several widget parameters. This vulnerability allows authenticated attackers with 'Contributor' level permissions or higher to inject arbitrary web scripts into a page. Because the scripts are stored on the server, they execute in the context of any user's browser who views the compromised page. The issue is present in all versions up to and including 3.35.5. A patch was released in version 3.35.6 to address the improper neutralization of alternate XSS syntax (CWE-87).
Affected products
- Elementor Elementor Website Builder – More Than Just a Page Builder up to, and including, 3.35.5
Timeline
- 2026-04-08: advisory: NVD publication date
- 2026-04-08: disclosed: Wordfence disclosure date
- 2026-04-08: patched: Version 3.35.6 released to address the issue
References
- https://plugins.trac.wordpress.org/browser/elementor/trunk/modules/wp-rest/classes/elementor-post-meta.php
- https://plugins.trac.wordpress.org/changeset?old_path=/elementor/tags/3.35.5&new_path=/elementor/tags/3.35.6
- https://www.wordfence.com/threat-intel/vulnerabilities/id/20232d70-72b2-47b7-ac7e-ad07892864ef?source=cve