Stored XSS Vulnerability in Magical Addons For Elementor by Noor Alam
CVE-2026-32429

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 March 2026

What is CVE-2026-32429?

A vulnerability in the Magical Addons For Elementor plugin allows for stored cross-site scripting (XSS) attacks due to improper neutralization of input during web page generation. Attackers can exploit this issue by injecting malicious scripts that may execute in the context of unsuspecting users, leading to unauthorized actions and exposure of sensitive data. This vulnerability affects versions of the plugin up to and including 1.4.1.

Affected Version(s)

Magical Addons For Elementor 0 <= 1.4.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abu Hurayra | Patchstack Bug Bounty Program
.