Junglewise Threat Intelligence

CVE-2026-8354: Gum Addon for Elementor stored XSS in pop_tag parameter

CVE-2026-8354 · Severity: medium · CVSS 6.4 · Published 2026-09-19

Executive brief

The Gum Addon for Elementor is a WordPress plugin that extends page-building functionality. A stored cross-site scripting vulnerability allows authenticated users with contributor-level access to inject malicious scripts that execute when other users view affected pages, potentially enabling account takeover, data theft, or malware distribution through compromised site content.

Technical details

The plugin fails to properly sanitize and escape user input from the 'pop_tag' parameter, allowing authenticated attackers with contributor-level permissions to store arbitrary JavaScript in the database. The stored payload executes in the context of any user viewing the affected page, including administrators. Exploitation requires valid WordPress authentication at contributor level or above.

Affected products

  • GumAd Gum Addon for Elementor up to and including 1.3.15

Timeline

  • 2026-09-19: disclosed

References