Executive brief
Exclusive Addons for Elementor is a popular WordPress plugin used to enhance website design. A security flaw allows users with basic contributor permissions to inject malicious scripts into page titles. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the post title parameter. This vulnerability exists in all versions up to and including 2.7.9.8. An authenticated attacker with Contributor-level access or higher can inject arbitrary web scripts into pages. These scripts are stored on the server and execute in the context of a user's browser whenever they access the compromised page. The flaw is specifically located within the post-duplicator extension of the plugin.
Affected products
- Exclusive Addons Exclusive Addons for Elementor up to, and including, 2.7.9.8
Timeline
- 2026-07-07: disclosed
- 2026-07-07: advisory
References
- https://plugins.trac.wordpress.org/browser/exclusive-addons-for-elementor/tags/2.7.9.8/extensions/post-duplicator.php
- https://plugins.trac.wordpress.org/browser/exclusive-addons-for-elementor/tags/2.7.9.8/extensions/post-duplicator.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/690fd38c-0e12-45f3-9055-51252e4809b1?source=cve