Stored Cross-Site Scripting Vulnerability in Themesflat Addons for Elementor Plugin
CVE-2026-39500
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-39500?
The Themesflat Addons for Elementor plugin contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into web pages. This vulnerability arises from improper neutralization of user input during web page generation, which can lead to severe security issues for affected websites. The vulnerability affects versions of the plugin up to and including 2.3.2, and it is crucial for users to ensure they are running a patched version to prevent potential exploitation.
Affected Version(s)
themesflat-addons-for-elementor 0 <= 2.3.2