Cross-Site Scripting Vulnerability in Elementor WooCommerce Builder Addons by Mamunur Rashid
CVE-2026-95596
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 October 2026
What is CVE-2026-95596?
A Cross-Site Scripting (XSS) vulnerability exists in the ShopBuilder β Elementor WooCommerce Builder Addons, allowing attackers to inject malicious scripts into web pages. This flaw allows for the exploitation of untrusted user inputs leading to potential session hijacking and information theft. The vulnerability affects versions up to 3.4.1, posing a risk to users who have not updated their plugins. Proper sanitization of inputs is essential to mitigate this risk and secure applications against unauthorized access.
Affected Version(s)
ShopBuilder β Elementor WooCommerce Builder Addons 0 <= 3.4.1