Junglewise Threat Intelligence

CVE-2026-83541: Sina Extension for Elementor stored XSS in Table widget

CVE-2026-83541 · Severity: medium · CVSS 6.8 · Published 2026-09-09

Executive brief

Sina Extension for Elementor is a WordPress plugin that adds custom page-building widgets to the Elementor page builder. A flaw in the Table widget fails to properly escape user input in table headers, allowing contributors and higher-level users to inject malicious scripts. When other users view the affected page, the injected code executes in their browsers, potentially stealing session data or performing actions on their behalf.

Technical details

This is a Stored Cross-Site Scripting (XSS) vulnerability in the Sina Extension for Elementor plugin. The root cause is insufficient HTML escaping of the Table widget's header text setting before it is output as an HTML attribute. The attack requires an authenticated user with Contributor role or higher. The attacker crafts a malicious payload in the table header (e.g., x' onmouseover='alert(document.domain)' data-x=') which is stored in the page draft. When editors or administrators view or preview the page, the payload executes in their browser context. The vulnerability is fixed in version 3.10.4.

Affected products

  • Sina Systems Extension for Elementor 3.7.1 to 3.10.3

Timeline

  • 2026-09-07: disclosed
  • 2026-09-09: advisory
  • 2026-09-09: patched: Fixed in version 3.10.4

References