Executive brief
Essential Addons for Elementor is a popular WordPress plugin used to add advanced design elements to websites. A security flaw in the Pricing Table widget allows users with basic editing permissions (Contributor level) to inject malicious scripts into a page. If an administrator views or previews the affected page, these scripts could execute in their browser, potentially leading to unauthorized actions or site takeover.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Pricing Table widget of the Essential Addons for Elementor plugin due to insufficient validation of the 'eael_pricing_table_title_tag' parameter. While the title body is sanitized, the HTML tag name itself is output via esc_html() without adequate filtering of the tag name position. An attacker with Contributor-level privileges can bypass standard WordPress KSES filtering by injecting a payload into the tag name field (e.g., using an 'img' tag with an 'onerror' attribute). This script executes when the post is viewed or previewed by other users, including administrators. The issue is fixed in version 6.6.10.
Affected products
- WPDeveloper Essential Addons for Elementor - Lite < 6.6.10
Timeline
- 2026-07-13: disclosed: Publicly published by WPScan
- 2026-07-13: patched: Fixed in version 6.6.10
- 2026-07-30: advisory: NVD published date