Executive brief
The Qi Addons For Elementor plugin, used to extend WordPress page-building capabilities, contains a reflected cross-site scripting (XSS) vulnerability in its search functionality. An attacker can craft a malicious URL that, when visited by a user, executes arbitrary JavaScript in the victim's browser—potentially stealing session credentials, performing unauthorized actions, or defacing page content. The vulnerability requires specific plugin configuration (Table of Contents widget enabled on search results pages) but affects all versions up to 1.11.
Technical details
The vulnerability is a reflected XSS in the 's' parameter (search query) due to insufficient input sanitization and output escaping. The Table of Contents widget, when placed on search-results templates with the 'Limit ToC to Main Page Content' option disabled, scans and reflects the unsanitized search parameter in page headings without proper HTML escaping. An unauthenticated attacker can inject arbitrary JavaScript by crafting a malicious search URL; the payload executes in the browser of any user who accesses the injected link. No authentication is required. A patch should be available in versions after 1.11.
Affected products
- Qi Addons For Elementor up to and including 1.11
Timeline
- 2026-09-18: disclosed