Cross-site Scripting Flaw in BdThemes Element Pack for Elementor
CVE-2026-105873
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 October 2026
What is CVE-2026-105873?
A Cross-site Scripting vulnerability exists in the BdThemes Element Pack for Elementor, allowing attackers to execute arbitrary scripts in the context of a user's session. The flaw occurs due to improper neutralization of input during the page generation process, which could lead to the storage of malicious scripts in the database. This vulnerability affects versions of Element Pack Elementor Addons from n/a through 8.8.6, posing a risk to users who may be exposed to malicious content if exploited.
Affected Version(s)
Element Pack Elementor Addons 0 <= 8.8.6