Junglewise Threat Intelligence

CVE-2026-6565: AnalogWP Style Kits Stored XSS in kit title parameter

CVE-2026-6565 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Technologies: AnalogWP Style Kits. Vendors: AnalogWP.

Executive brief

The Style Kits plugin for WordPress, which provides design templates and theme styling for the Elementor page builder, contains a security flaw. This vulnerability allows users with low-level account access (such as contributors) to inject malicious scripts into the website's administrative interface or public pages. If exploited, these scripts could be used to redirect visitors to malicious sites, steal session information, or perform unauthorized actions on behalf of other users who view the affected content.

Technical details

The Style Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'kit title' parameter within the '/wp-json/agwp/v1/tokens/save' REST API endpoint. Authenticated attackers with contributor-level permissions or higher can submit malicious JavaScript that is stored in the database. This script then executes in the browser of any user (including administrators) who accesses the page where the kit title is rendered. The vulnerability exists in all versions up to and including 2.5.0. A patch has been identified in the plugin's development repository.

Affected products

  • AnalogWP Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns Up to, and including, 2.5.0

Timeline

  • 2026-05-27: advisory: NVD publication date
  • 2026-05-26: disclosed: Wordfence initial disclosure

References

Related threats