Junglewise Threat Intelligence

CVE-2026-6459: WPDeveloper Essential Addons for Elementor Stored XSS in Event Calendar

CVE-2026-6459 · Severity: medium · CVSS 6.4 · Published 2026-07-08

Technologies: WPDeveloper Essential Addons for Elementor, WPDeveloper (wpdevteam) Essential Addons for Elementor – Popular Elementor Templates & Widgets. Vendors: WPDeveloper.

Executive brief

Essential Addons for Elementor is a popular WordPress plugin used to add custom design elements and widgets to websites. A security flaw in its Event Calendar widget allows users with 'Author' level permissions or higher to inject malicious scripts into website pages. When other users or visitors view these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Essential Addons for Elementor plugin due to insufficient input sanitization and output escaping on event titles sourced from 'The Events Calendar' within the Event Calendar widget. The vulnerability is classified as CWE-79. An authenticated attacker with Author-level privileges or higher can inject malicious JavaScript into event titles. Because the plugin fails to properly neutralize this input before it is rendered on the page, the script executes in the context of any user's browser who views the calendar. This can lead to session hijacking or unauthorized administrative actions if a site administrator views the page. A fix was introduced in version 6.6.3 (implied by the changeset reference).

Affected products

  • WPDeveloper (wpdevteam) Essential Addons for Elementor – Popular Elementor Templates & Widgets up to, and including, 6.6.2

Timeline

  • 2026-07-08: advisory: Published by Wordfence and NVD

References

Related threats