Executive brief
ElementsKit is a popular WordPress plugin used to add advanced design features and templates to websites. A security flaw allows users with basic contributor-level access to embed malicious scripts into website pages. When other visitors or administrators view these pages, the scripts can run automatically, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'ekit_tab_title' parameter within the Simple Tab widget. This vulnerability allows authenticated attackers with contributor-level permissions or higher to inject arbitrary web scripts into a page. Because the input is stored on the server, the script executes in the browser of any user who navigates to the affected page. The issue is present in all versions up to and including 3.7.9. A patch appears to have been addressed in subsequent updates (referenced in changeset 3468265).
Affected products
- roxnor ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor <= 3.7.9
Timeline
- 2026-04-04: disclosed: Initial publication of the CVE record
- 2026-04-04: advisory: Wordfence published the vulnerability details