Executive brief
A popular WordPress plugin used for website design is vulnerable to a security flaw that allows users with low-level editing permissions to inject malicious scripts. These scripts are triggered when a site administrator or high-privileged user opens the affected page within the Elementor editor. This could lead to unauthorized actions being performed on behalf of the administrator, potentially compromising the website's security or data.
Technical details
The vulnerability is a Stored Cross-Site Scripting (XSS) flaw residing in the 'premium_tooltip_text' parameter due to insufficient input sanitization and output escaping. Authenticated attackers with contributor-level permissions or higher can inject arbitrary web scripts. The exploit is specifically triggered via the print_template() method registered on the 'elementor/section/print_template' hook, meaning the payload executes when a high-privileged user (like an administrator) opens the affected post within the Elementor editor interface rather than on the public frontend. A patch was introduced in version 4.11.85.
Affected products
- Leap13 Premium Addons for Elementor – Powerful Elementor Templates & Widgets up to, and including, 4.11.84
Timeline
- 2026-07-11: advisory: Published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.82/addons/tooltips.php
- https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.82/addons/tooltips.php
- https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.82/addons/tooltips.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3597629%40premium-addons-for-elementor&new=3597629%40premium-addons-for-elementor
- https://www.wordfence.com/threat-intel/vulnerabilities/id/867a0742-4fa9-4473-8d51-9abb6ec353a8?source=cve