Junglewise Threat Intelligence

CVE-2026-14817: Element Pack Elementor Addons stored XSS via uikit data attributes

CVE-2026-14817 · Severity: medium · CVSS 6.8 · Published 2026-08-02

Vendors: BdThemes.

Executive brief

Element Pack is a popular WordPress plugin that adds advanced UI components to the Elementor page builder. The plugin fails to properly sanitize user input in certain data attributes, allowing contributors and higher-privilege users to embed malicious JavaScript code in posts and pages. When any visitor—including administrators and unauthenticated users—views the affected content, the injected script executes in their browser, potentially compromising their session and account.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the bundled UIKit front-end library integration. The plugin does not sanitize option values passed through data attributes (specifically `data-bdt-lightbox` and related attributes) before the UIKit library re-parses and renders them in the browser. Attackers with contributor-level access or higher can inject arbitrary JavaScript through custom HTML blocks using payloads that encode or obfuscate HTML entities (e.g., `<` and `>`), which survive server-side sanitization and are decoded back to executable code client-side. The vulnerability affects all front-end pages by default, and the payload persists in the database, executing against every subsequent visitor. The issue is fixed in version 8.7.13.

Affected products

  • BdThemes Element Pack Elementor Addons before 8.7.13

Timeline

  • 2026-07-21: disclosed
  • 2026-08-02: advisory
  • 2026-08-02: patched: Fixed in version 8.7.13

References

Related threats