Executive brief
The Plus Addons for Elementor, a popular WordPress plugin used to extend website design capabilities, contains a security flaw in its Button widget. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into pages. If exploited, these scripts could execute in the browsers of other site visitors or administrators, potentially leading to unauthorized actions or data theft.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in The Plus Addons for Elementor plugin due to insufficient input sanitization in the Button widget. The 'render' function in 'modules/widgets/tp_button.php' processes the 'custom_attributes' setting through the 'tp_senitize_js_input()' filter, which can be bypassed. Authenticated attackers with Contributor-level permissions or higher can exploit this to inject arbitrary web scripts into pages. These scripts execute whenever a user visits the affected page. The issue is resolved in version 6.4.12.
Affected products
- POSIMYTH Innovations The Plus Addons for Elementor up to and including 6.4.11
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory
- 2026-07-10: patched: Patched in version 6.4.12
References
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/6.4.10/modules/helper-function.php
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/6.4.10/modules/widgets/tp_button.php
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/6.4.11/modules/widgets/tp_button.php
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/6.4.12/modules/widgets/tp_button.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3c3217f9-67e5-488d-b80a-49a61678fb98?source=cve