Junglewise Threat Intelligence

CVE-2026-9243: POSIMYTH The Plus Addons for Elementor Stored XSS in Carousel Anything

CVE-2026-9243 · Severity: medium · CVSS 6.4 · Published 2026-05-29

Technologies: POSIMYTH Innovations The Plus Addons for Elementor. Vendors: POSIMYTH Innovations.

Executive brief

The Plus Addons for Elementor, a popular WordPress plugin used to enhance website design, contains a security flaw in its Carousel Anything widget. This vulnerability allows users with basic contributor-level access to inject malicious scripts into website pages. When other visitors or administrators view these pages, the scripts can execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient output escaping in the render() function of the Carousel Anything widget. Specifically, the 'carousel_direction' parameter is placed into an unquoted HTML 'dir' attribute. While the plugin uses esc_attr(), the lack of quotes around the attribute allows for attribute injection. Authenticated attackers with contributor-level permissions or higher can exploit this to inject arbitrary web scripts. These scripts execute in the context of any user's browser who visits the affected page. The issue is addressed in version 6.4.16.

Affected products

  • POSIMYTH Innovations The Plus Addons for Elementor up to, and including, 6.4.15

Timeline

  • 2026-05-29: advisory: NVD publication date
  • 2026-05-29: disclosed: Wordfence vulnerability report published
  • 2026-05-29: patched: Version 6.4.16 released to address the issue

References

Related threats