Executive brief
WPZOOM Addons for Elementor is a WordPress plugin that provides additional design widgets for the Elementor website builder. A security flaw in versions 1.3.4 and earlier allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks a specially crafted link, the attacker could steal session information, redirect users to malicious sites, or perform unauthorized actions on the website.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the WPZOOM Addons for Elementor plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw is present in versions up to and including 1.3.4. An unauthenticated remote attacker can exploit this by tricking a user into interacting with a malicious link or visiting a crafted page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 1.3.5.
Affected products
- WPZOOM WPZOOM Addons for Elementor <= 1.3.4
Timeline
- 2026-02-11: other: Reported by Nguyen Ba Khanh
- 2026-04-16: disclosed: Vulnerability disclosed by Patchstack
- 2026-06-17: advisory: NVD publication date
- 1.3.5: patched: Fixed in version 1.3.5