Junglewise Threat Intelligence

CVE-2026-15145: WPDeveloper Essential Addons for Elementor Stored XSS in Fancy Text Widget

CVE-2026-15145 · Severity: medium · CVSS 6.4 · Published 2026-07-21

Technologies: WPDeveloper Essential Addons for Elementor, WPDeveloper Essential Addons for Elementor – Popular Elementor Templates & Widgets. Vendors: WPDeveloper.

Executive brief

Essential Addons for Elementor is a popular WordPress plugin used to add custom design elements and widgets to websites. A security flaw in the plugin's Fancy Text widget allows users with contributor-level access or higher to inject malicious scripts into website pages. If exploited, these scripts will run automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Essential Addons for Elementor plugin for WordPress due to insufficient input sanitization and output escaping within the Fancy Text Widget. Specifically, the vulnerability is located in the handling of animation names within the Morphext library and the fancy-text.js component. Authenticated attackers with contributor-level permissions or higher can inject arbitrary web scripts into pages. These scripts execute in the context of a user's browser whenever they visit the compromised page. The issue is addressed in version 6.7.0 by implementing proper sanitization for animation names.

Affected products

  • WPDeveloper Essential Addons for Elementor – Popular Elementor Templates & Widgets up to, and including, 6.6.11

Timeline

  • 2026-07-21: advisory: NVD publication date
  • 2026-07-21: disclosed: Wordfence disclosure date

References

Related threats