Junglewise Threat Intelligence

CVE-2026-57376: Element Invader ElementInvader Addons DOM-based XSS

CVE-2026-57376 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

ElementInvader Addons is a WordPress plugin that provides additional design components for the Elementor page builder. A security flaw in this plugin allows attackers to inject malicious scripts into a website, which could lead to unauthorized actions being performed in the context of a user's browser, such as stealing session cookies or redirecting visitors to malicious sites. This typically occurs when a victim clicks a specially crafted link or visits a compromised page.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the ElementInvader Addons for Elementor plugin due to improper neutralization of input during web page generation. The flaw allows an unauthenticated attacker to inject malicious scripts into the Document Object Model (DOM) environment. Successful exploitation requires user interaction, such as a privileged user clicking a malicious link. Once executed, the script can access sensitive information like session tokens or perform actions on behalf of the user. The issue is addressed in version 1.4.4.

Affected products

  • Element Invader ElementInvader Addons for Elementor n/a through 1.4.3

Timeline

  • 2026-04-23: disclosed: Reported by Evan NR to Patchstack
  • 2026-07-07: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE record
  • 2026-07-07: patched: Version 1.4.4 released to address the issue

References