Executive brief
Themesflat Addons for Elementor is a WordPress plugin used to add custom design elements to websites. A security flaw allows an attacker with basic contributor-level access to inject malicious scripts into website pages. If a site visitor or administrator views the affected page, the script could redirect them to malicious sites, display unauthorized advertisements, or potentially steal session information.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Themesflat Addons for Elementor plugin for WordPress due to improper neutralization of input during web page generation. An attacker with 'Contributor' or higher privileges can inject malicious scripts into the database. These scripts are then executed in the browser of any user who visits the affected page. The vulnerability requires some user interaction (viewing the page) and has been assigned a CVSS score of 6.5. The issue is resolved in version 2.3.3.
Affected products
- Themesflat Themesflat Addons for Elementor <= 2.3.2
Timeline
- 2026-02-21: other: Reported by researcher timomangcut
- 2026-03-23: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD
- 2026-03-23: patched: Version 2.3.3 released to address the vulnerability