Stored Cross-Site Scripting Vulnerability in Gum Addon for Elementor by WordPress
CVE-2026-8354
6.4MEDIUM
What is CVE-2026-8354?
The Gum Addon for Elementor plugin for WordPress is prone to a Stored Cross-Site Scripting issue through the 'pop_tag' parameter. This flaw arises from inadequate input sanitization and output escaping in versions up to and including 1.3.15. Authenticated attackers with contributor-level access or higher can exploit this vulnerability to inject malicious web scripts into pages. These scripts execute automatically when a user visits the compromised page, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
Gum Addon for Elementor 0 <= 1.3.15