Cross-Site Scripting Vulnerability in Biggop Library from Sigmative API
CVE-2026-92991

5.4MEDIUM

What is CVE-2026-92991?

The Biggop Library is susceptible to Cross-Site Scripting (XSS) through the 'display_id' parameter of the Sigmative API. This vulnerability arises from inadequate output escaping, allowing attackers to execute arbitrary web scripts on affected pages if they manage to compromise the Sigmative API server. Consequently, users accessing these compromised pages may unknowingly execute malicious scripts, posing serious security risks to their data and privacy.

Affected Version(s)

Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons 0 <= 8.7.14

Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator 0 <= 1.5.6

Pixel Gallery Addons for Elementor 0 <= 2.1.14

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.