Stored Cross-Site Scripting Vulnerability in ElementsKit Pro Plugin for WordPress
CVE-2026-4246

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 August 2026

What is CVE-2026-4246?

The ElementsKit Pro plugin for WordPress is prone to Stored Cross-Site Scripting vulnerabilities through the 's' parameter of the Advanced Search REST endpoint. This flaw results from inadequate input sanitization and improper output escaping, allowing unauthorized access to the REST endpoint. Unsanitized search terms are stored and later rendered in HTML attributes, creating opportunities for attackers to execute arbitrary scripts when users interact with the search widget. This can lead to serious security concerns for websites utilizing this plugin, as attackers can leverage these scripts to manipulate the user experience.

Affected Version(s)

ElementsKit Pro 0 <= 4.10.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ren Voza
.