Junglewise Threat Intelligence

CVE-2026-11603: Product Filter Widget for Elementor Reflected XSS in filterFormArray

CVE-2026-11603 · Severity: medium · CVSS 6.1 · Published 2026-06-09

Vendors: Unknown.

Executive brief

The Product Filter Widget for Elementor, a WordPress plugin used to add product filtering capabilities to websites, contains a security flaw that allows for reflected cross-site scripting. An attacker can exploit this by tricking a user into clicking a malicious link or visiting a specially crafted webpage. If successful, the attacker can execute malicious scripts in the user's browser, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

The vulnerability is a Reflected Cross-Site Scripting (XSS) flaw residing in the 'args[filterFormArray]' parameter of the Product Filter Widget for Elementor plugin. The root cause is insufficient input sanitization and output escaping within the AJAX handler registered via 'wp_ajax_nopriv_'. Because the affected endpoint lacks nonce verification and capability checks, an unauthenticated attacker can deliver a payload via a CSRF-style form auto-submission to the 'admin-ajax.php' endpoint. Exploitation requires a victim to visit an attacker-controlled page or click a malicious link, resulting in the execution of arbitrary JavaScript in the context of the victim's browser.

Affected products

  • Unknown Product Filter Widget for Elementor Up to and including 1.0.6

Timeline

  • 2026-06-09: advisory: Advisory published by Wordfence and NVD

References

Related threats