CVE-2026-103063: WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/elementskit-liteto a version that resolves this vulnerability.Fixed in 4.0.7
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack vector is network-based, but exploitation requires low-level privileges and user interaction. The provided data does not identify the specific WordPress role or interaction required.
Are sites running the Lite edition affected by default?
The issue affects ElementsKit Elementor addons Lite through version 4.0.6. The provided data does not state whether a particular feature must be enabled or whether the vulnerable behavior is reachable in a default configuration.
What is the potential impact if exploitation succeeds?
This is a stored XSS vulnerability with low impacts to confidentiality, integrity, and availability, and scope changed. Successful exploitation could cause attacker-supplied script to be stored and later run when a victim interacts with affected content.