Junglewise Threat Intelligence

CVE-2026-85302: WPKoi Templates for Elementor DOM-based cross-site scripting

CVE-2026-85302 · Severity: medium · CVSS 6.5 · Published 2026-09-03

Executive brief

WPKoi Templates for Elementor is a WordPress plugin that provides page design templates for the Elementor page builder. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts into affected websites, potentially stealing visitor data or hijacking user accounts. The vulnerability requires user interaction, such as clicking a malicious link or visiting a crafted page, to be exploited.

Technical details

The vulnerability is a DOM-based cross-site scripting (XSS) flaw in WPKoi Templates for Elementor version 3.7.2 and earlier. The issue stems from improper neutralization of user input during web page generation, allowing attackers to inject arbitrary JavaScript code that executes in the context of a user's browser. Exploitation requires a privileged user (Contributor or Developer role) to perform an action such as clicking a malicious link or visiting a crafted page. An attacker can leverage this to steal visitor data, hijack accounts, or perform unauthorized actions on behalf of affected users. The vulnerability was patched in version 3.7.3.

Affected products

  • WPKoi WordPress Themes WPKoi Templates for Elementor through 3.7.2

Timeline

  • 2026-07-17: disclosed: Vulnerability reported by Abdullah Kareem
  • 2026-09-03: advisory: Published by Patchstack and NVD
  • 2026-09-03: patched: Fixed in version 3.7.3

References