Junglewise Threat Intelligence

CVE-2026-11390: BlazeThemes News Kit Addons For Elementor stored XSS in multiple widgets

CVE-2026-11390 · Severity: medium · CVSS 6.4 · Published 2026-07-14

Executive brief

The News Kit Addons For Elementor plugin for WordPress, which provides additional design elements for website building, contains a security flaw in its Site Logo Title and Single Author Box widgets. An attacker with basic contributor-level access to the website can inject malicious scripts into pages. When other users or administrators visit these pages, the scripts will execute, potentially leading to unauthorized actions or data theft.

Technical details

This vulnerability is a Stored Cross-Site Scripting (XSS) flaw residing in the Site Logo Title and Single Author Box widgets of the News Kit Addons For Elementor plugin. The root cause is insufficient input sanitization and output escaping of user-supplied data. Authenticated attackers with contributor-level permissions or higher can exploit this by intercepting and modifying the 'elementor_ajax' AJAX save request to bypass client-side SELECT control restrictions. This allows the submission of arbitrary tag-name values containing malicious scripts, which are then stored and executed in the context of any user viewing the affected page. The issue is addressed in version 1.4.7.

Affected products

  • blazethemes News Kit Addons For Elementor up to, and including, 1.4.6

Timeline

  • 2026-07-14: advisory: NVD publication date
  • 2026-07-14: disclosed: Wordfence disclosure date
  • 2026-07-14: patched: Version 1.4.7 released to address the issue

References