Junglewise Threat Intelligence

CVE-2026-4246: ElementsKit Pro stored XSS in Advanced Search

CVE-2026-4246 · Severity: medium · CVSS 6.1 · Published 2026-08-28

Executive brief

ElementsKit Pro is a popular WordPress plugin that provides site search and UI building features. The Advanced Search widget contains a flaw that allows attackers to inject malicious scripts into the search functionality without authentication. When visitors use the search feature and see popular keywords, the injected scripts execute in their browser, potentially stealing credentials or redirecting them to malicious sites.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the Advanced Search REST endpoint (/wp-json/elementskit/v1/advanced-search). The endpoint is accessible to unauthenticated users and accepts a 's' parameter (search term) without proper sanitization. While sanitize_text_field() is applied, it does not encode double quotes, and the stored keywords are rendered directly in HTML attributes via sprintf() without escaping (missing esc_attr()). An unauthenticated attacker can inject arbitrary JavaScript by submitting a malicious search term; the script is stored in the WordPress database and executes in the browsers of users who view the "no results" popular keywords view on pages using the Advanced Search widget. Patches are available in version 4.10.2 and later.

Affected products

  • ElementsKit ElementsKit Pro up to 4.10.1

Timeline

  • 2026-08-28: disclosed

References