Junglewise Threat Intelligence

CVE-2026-5243: POSIMYTH The Plus Addons for Elementor stored XSS in Navigation Menu Lite

CVE-2026-5243 · Severity: medium · CVSS 6.4 · Published 2026-05-14

Technologies: POSIMYTH Innovations The Plus Addons for Elementor. Vendors: POSIMYTH Innovations.

Executive brief

The Plus Addons for Elementor, a popular WordPress plugin used for building custom website layouts and menus, contains a security flaw in its Navigation Menu Lite widget. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into website pages. When other users, including site administrators or visitors, view these pages, the scripts will execute in their browsers, potentially leading to unauthorized actions or data theft.

Technical details

The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'menu_hover_click' parameter within the Navigation Menu Lite widget. This vulnerability exists in all versions up to and including 6.4.11. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into a page. These scripts will execute in the context of any user's browser who visits the affected page. The issue was addressed in version 6.4.12 by implementing proper sanitization and escaping functions.

Affected products

  • POSIMYTH Innovations The Plus Addons for Elementor Up to, and including, 6.4.11

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory

References

Related threats