Stored Cross-Site Scripting Vulnerability in Essential Addons for Elementor by WPDevelopers
CVE-2026-15145
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 July 2026
What is CVE-2026-15145?
The Essential Addons for Elementor plugin allows authenticated users with contributor-level access and above to exploit a stored cross-site scripting vulnerability. By leveraging the Fancy Text Widget and exploiting insufficient input sanitization and output escaping, attackers can inject malicious web scripts into pages, which are subsequently executed when users access the affected pages. This poses a significant risk to the security of WordPress sites using this plugin, making it imperative for administrators to update to the latest version to mitigate potential threats.
Affected Version(s)
Essential Addons for Elementor β Popular Elementor Templates & Widgets 0 <= 6.6.11