Cross Site Scripting Vulnerability in Ultimate Addons for Elementor by WPDeveloper
CVE-2026-66688

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 August 2026

What is CVE-2026-66688?

The Ultimate Addons for Elementor plugin has a Cross Site Scripting (XSS) vulnerability in versions up to 1.45.2. This flaw allows attackers to inject malicious scripts into the web pages viewed by users. If exploited, it could lead to unauthorized actions within the user's browser session, posing a significant security risk to WordPress sites using the plugin. Promptly updating to the latest version is recommended to mitigate this vulnerability and enhance the robust security of your web application.

Affected Version(s)

Ultimate Addons for Elementor <= 1.45.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh - HPT Vietnam Corporation | Patchstack Bug Bounty Program
.