Reflected Cross-Site Scripting in Qi Addons For Elementor Plugin by WordPress
CVE-2026-92249
6.1MEDIUM
What is CVE-2026-92249?
The Qi Addons For Elementor plugin for WordPress is susceptible to a reflective cross-site scripting vulnerability due to inadequate input validation on the 's' parameter. Any unauthenticated attacker can exploit this flaw, allowing them to inject malicious JavaScript code into pages. When users navigate to affected pages, these scripts can execute in their browsers, potentially leading to various harmful outcomes. The vulnerability is triggered when the Table of Contents widget appears on templates like sitewide headers or footers, with the setting for 'Limit ToC to Main Page Content' set to its default value, enabling the widget to improperly handle unfiltered inputs.
Affected Version(s)
Qi Addons For Elementor 0 <= 1.11