Junglewise Threat Intelligence

CVE-2026-8613: aThemes Addons for Elementor Stored XSS in title_tag setting

CVE-2026-8613 · Severity: medium · CVSS 6.4 · Published 2026-06-10

Technologies: aThemes Addons for Elementor. Vendors: aThemes.

Executive brief

The aThemes Addons for Elementor plugin for WordPress, which provides additional design elements for website building, contains a security flaw. An attacker with contributor-level access or higher can inject malicious scripts into specific website widgets like the Posts Timeline or Posts Carousel. These scripts will then run automatically in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'title_tag' setting in several widgets, including Posts Timeline and Posts Carousel (Default, Banner, and Modern skins). The vulnerability stems from a failure to implement whitelist validation or proper output escaping on user-supplied input, unlike the Posts List widget which is correctly secured. An authenticated attacker with contributor-level permissions can exploit this over the network to inject arbitrary JavaScript. This script executes in the context of any user's browser session when they visit the compromised page. The issue is addressed in version 1.1.9.

Affected products

  • aThemes aThemes Addons for Elementor up to, and including, 1.1.8

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References