Executive brief
A security vulnerability exists in the Sina Extension for Elementor, a popular WordPress plugin used to add custom widgets and design elements to websites. An attacker can send a specially crafted link to a user; if the user clicks it, the attacker can execute malicious code in their web browser. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive information like session cookies.
Technical details
The Sina Extension for Elementor plugin suffers from a reflected Cross-Site Scripting (XSS) vulnerability in its 'sina_load_more_posts' AJAX handler. The vulnerability arises because the plugin fails to properly escape user-supplied input within the 'posts_data' parameter, specifically the 'read_more_text' field, before reflecting it into the HTML response. While the plugin uses 'sanitize_text_field', attackers can bypass this by using JSON Unicode escapes (e.g., \u003c) which are subsequently restored to literal angle brackets by 'json_decode()' at the sink. An unauthenticated attacker can exploit this by scraping a deterministic guest nonce from a public page and crafting a request that executes arbitrary JavaScript in the context of the victim's browser. The issue is fixed in version 3.10.2.
Affected products
- Sina Extra Sina Extension for Elementor < 3.10.2
Timeline
- 2026-07-06: disclosed: Publicly published by WPScan
- 2026-07-27: advisory: NVD publication date