Executive brief
The Ultimate Addons for Elementor plugin for WordPress, which provides additional design widgets for the Elementor page builder, contains a security flaw in its Navigation Menu widget. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into website pages. When other users or visitors view these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.
Technical details
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'data-toggle-icon' and 'data-close-icon' attributes within the Navigation Menu Widget. While the WordPress function 'wp_kses_post' is applied on save, it fails to neutralize HTML-entity-encoded payloads stored inside data-* attributes. These payloads are subsequently decoded by the browser and rendered as active markup via jQuery's .html() method. An authenticated attacker with contributor-level permissions can exploit this to inject malicious JavaScript. The issue is addressed in version 2.9.2.
Affected products
- Brainstorm Force Ultimate Addons for Elementor Up to and including 2.9.1
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory
References
- https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.8.8/inc/js/frontend.js
- https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.8.8/inc/js/frontend.js
- https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.8.8/inc/js/frontend.js
- https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.8.8/inc/js/frontend.js
- https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.9.1/inc/js/frontend.js
- https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.9.1/inc/js/frontend.js
- https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.9.1/inc/js/frontend.js