Executive brief
Ultimate Addons for Elementor is a popular WordPress plugin that extends the Elementor page builder with additional design and functionality elements. A Cross Site Scripting (XSS) vulnerability in versions up to 1.45.2 allows a contributor-level user to inject malicious scripts that could steal visitor data or hijack user accounts. The flaw requires user interaction (e.g., clicking a malicious link) to be exploited, and has been patched in version 1.45.2.1.
Technical details
This is a Contributor-level Stored or Reflected Cross Site Scripting (XSS) vulnerability in Ultimate Addons for Elementor plugin versions through 1.45.2. The vulnerability allows an authenticated user with Contributor privilege to inject malicious JavaScript that executes in the browser context of other users visiting the affected site. The attack requires user interaction or social engineering to trigger the payload. The vulnerable component processes user input without proper sanitization or escaping. This vulnerability was patched in version 1.45.2.1. Site administrators should update immediately.
Affected products
- Brainstorm Force Ultimate Addons for Elementor <=1.45.2
Timeline
- 2026-07-24: disclosed: Vulnerability reported to Patchstack
- 2026-07-29: patched: Patch released (version 1.45.2.1)
- 2026-08-06: advisory: CVE-2026-66688 published