Junglewise Threat Intelligence

CVE-2026-66574: BdThemes Element Pack Elementor Addons contributor XSS

CVE-2026-66574 · Severity: medium · CVSS 6.5 · Published 2026-09-17

Vendors: BdThemes.

Executive brief

Element Pack Elementor Addons is a popular WordPress plugin that provides additional components for the Elementor page builder. A cross-site scripting vulnerability allows contributors with plugin access to inject malicious scripts that could steal visitor data or hijack user accounts when other users interact with affected pages.

Technical details

The plugin versions 8.8.3 and earlier are vulnerable to a contributor-level cross-site scripting (XSS) vulnerability due to insufficient input sanitization. An attacker with contributor or higher privileges can inject malicious JavaScript code into the site. The vulnerability requires user interaction (such as a visitor clicking a malicious link or visiting a crafted page), and successful exploitation allows script injection that can steal visitor cookies, session tokens, or perform actions on behalf of compromised users. The issue was patched in version 8.8.4.

Affected products

  • BdThemes Element Pack Elementor Addons <=8.8.3

Timeline

  • 2026-09-14: disclosed: Vulnerability reported to Patchstack
  • 2026-09-17: advisory: Published by Patchstack and NVD as CVE-2026-66574
  • 2026-09-17: patched: Fix available in version 8.8.4

References

Related threats