Junglewise Threat Intelligence

CVE-2026-57620: Tim Strifler Exclusive Addons Elementor Stored XSS

CVE-2026-57620 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Technologies: Tim Strifler Exclusive Addons for Elementor. Vendors: Tim Strifler.

Executive brief

Exclusive Addons Elementor is a popular WordPress plugin used to add custom design elements and widgets to websites. A security vulnerability in this plugin allows an attacker with basic contributor-level access to inject malicious scripts into web pages. If a site administrator or visitor views the affected page, the script could execute, potentially leading to unauthorized redirects, malicious advertisements, or the theft of sensitive session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Tim Strifler Exclusive Addons Elementor plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw allows an authenticated attacker with 'Contributor' or higher privileges to inject arbitrary web scripts into the database. These scripts are subsequently executed in the browser of any user (including administrators) who views the affected content. The vulnerability requires minimal user interaction (viewing the page) and is addressed in version 2.7.9.9.

Affected products

  • Tim Strifler Exclusive Addons Elementor up to 2.7.9.8

Timeline

  • 2026-02-01: other: Reported by Nguyen Ba Khanh
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Version 2.7.9.9 released to address the issue

References

Related threats