Cross-site Scripting Vulnerability in BdThemes Element Pack for Elementor
CVE-2026-105871
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 October 2026
What is CVE-2026-105871?
A security vulnerability in the BdThemes Element Pack for Elementor Addons allows for stored cross-site scripting (XSS). This occurs due to improper neutralization of user input during web page generation. As a result, attackers could exploit this flaw to inject malicious scripts into the affected products, compromising user data and security. Versions affected range from not applicable up to 8.8.6, emphasizing the need for prompt updates and security patches.
Affected Version(s)
Element Pack Elementor Addons 0 <= 8.8.6