Stored Cross-Site Scripting Vulnerability in Elementor Website Builder for WordPress
CVE-2026-6127
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 May 2026
What is CVE-2026-6127?
The Elementor Website Builder plugin for WordPress has a vulnerability that allows stored cross-site scripting due to inadequate input sanitization of the _elementor_data meta field. This issue arises when the plugin processes form-encoded REST API requests without proper sanitization, leaving the door open for authenticated users with contributor-level access to inject malicious scripts. The unsanitized data can be stored and output through various widget components, creating a risk for users accessing affected pages.
Affected Version(s)
Elementor Website Builder β more than just a page builder 0 <= 4.0.4