Stored Cross-Site Scripting Vulnerability in Sina Extension for Elementor by WordPress
CVE-2026-83541
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-83541?
The Sina Extension for Elementor, a popular WordPress plugin, is vulnerable to Stored Cross-Site Scripting due to inadequate escaping of HTML attributes in the Table widget settings. This flaw could be exploited by users with Contributor roles or higher to inject malicious scripts, potentially compromising site integrity and user security.
Affected Version(s)
Sina Extension for Elementor 3.7.1 < 3.10.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.