Junglewise Threat Intelligence

CVE-2026-45437: Product Filter Widget for Elementor Cross Site Scripting

CVE-2026-45437 · Severity: high · CVSS 7.1 · Published 2026-06-15

Vendors: Unknown.

Executive brief

The Product Filter Widget for Elementor, a WordPress plugin used to add product filtering capabilities to websites, contains a security flaw that allows attackers to inject malicious scripts. If a site visitor or administrator clicks a specially crafted link, the attacker can execute code in their browser, potentially leading to unauthorized actions, data theft, or website redirection. As of the latest report, no official patch has been released by the developer.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Product Filter Widget for Elementor WordPress plugin (versions <= 1.0.6) due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is exploitable by unauthenticated remote attackers who can trick a user into interacting with a malicious link or crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to hijack sessions or deface pages. At the time of disclosure, no official patch is available, and users are advised to seek alternative mitigations or monitor for updates.

Affected products

  • Unknown Product Filter Widget for Elementor <= 1.0.6

Timeline

  • 2026-05-09: disclosed: Reported by Evan NR
  • 2026-06-01: advisory: Initial advisory published by Patchstack
  • 2026-06-15: advisory: NVD publication date

References

Related threats