Executive brief
WPBITS Addons For Elementor is a WordPress plugin that provides additional design elements for the Elementor page builder. A security flaw in this plugin allows an attacker with basic contributor-level access to inject malicious scripts into website pages. If a site administrator or visitor views the affected page, these scripts could redirect users to malicious sites, display unauthorized advertisements, or compromise the user's session.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the WPBITS Addons For Elementor Page Builder plugin due to improper neutralization of user input during web page generation. An attacker with 'Contributor' or higher privileges can inject malicious scripts into page content that are then stored on the server. The vulnerability is triggered when a privileged user (such as an administrator) interacts with the affected page or content. This issue affects all versions through 1.8.1; as of the advisory date, no official patch has been released.
Affected products
- wpbits WPBITS Addons For Elementor Page Builder <= 1.8.1
Timeline
- 2026-01-30: other: Vulnerability reported by researcher Abu Hurayra
- 2026-03-01: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD