Stored Cross-Site Scripting in Free Builder for Elementor Plugin by WordPress
CVE-2026-11767
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 July 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-11767?
The Free Builder for Elementor plugin for WordPress prior to version 1.6.7 is vulnerable to a stored cross-site scripting (XSS) flaw. This vulnerability arises because the plugin does not sanitize user input from contact form fields, allowing unauthenticated attackers to craft malicious payloads. When a logged-in administrator views the submissions in the admin dashboard, the injected scripts execute, potentially leading to further exploitation or compromise of the website.
Affected Version(s)
Free Theme Builder for Elementor 0 < 1.6.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.