Junglewise Threat Intelligence

CVE-2026-65503: bdthemes Ultimate Store Kit Elementor Addons XSS

CVE-2026-65503 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Vendors: BdThemes.

Executive brief

The Ultimate Store Kit Elementor Addons plugin for WordPress, which provides e-commerce design tools for the Elementor page builder, is vulnerable to a security flaw. An attacker with contributor-level access can inject malicious scripts into website pages. If a site administrator or visitor views these pages, the scripts could be used to redirect users to malicious sites, display unauthorized advertisements, or compromise user sessions.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Ultimate Store Kit Elementor Addons plugin for WordPress (versions <= 3.0.5) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with 'Contributor' privileges to inject malicious JavaScript payloads into the site's content. The vulnerability is triggered when a privileged user (such as an administrator) or a site visitor interacts with the affected page. This can lead to unauthorized script execution in the context of the victim's browser, potentially resulting in session hijacking or site defacement. The issue is addressed in version 3.0.7.

Affected products

  • bdthemes Ultimate Store Kit Elementor Addons <= 3.0.5

Timeline

  • 2026-01-09: other: Reported by Nguyen Ba Khanh
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date

References

Related threats