Executive brief
The Plus Addons for Elementor, a popular WordPress plugin used to extend the Elementor page builder with widgets and templates, is vulnerable to a security flaw. An attacker with contributor-level access can inject malicious scripts into website pages via the Progress Bar widget. These scripts will execute in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the Progress Bar shortcode. This vulnerability allows authenticated attackers with contributor-level permissions or higher to inject arbitrary web scripts into pages. These scripts are stored on the server and execute in the context of a user's browser session whenever they visit the compromised page. The issue affects all versions up to and including 6.4.9 and has been addressed in subsequent updates.
Affected products
- POSIMYTH Innovations The Plus Addons for Elementor up to, and including, 6.4.9
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory