CVE-2026-103084: WordPress Premium Addons for Elementor plugin <= 4.11.109 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeapWorx Premium Addons for Elementor premium-addons-for-elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.11.109.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Premium Addons for Elementorto a version that resolves this vulnerability.Fixed in 4.11.110
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges and user interaction. The attack can be conducted over the network with low attack complexity.
What is the potential impact if exploitation succeeds?
This is a stored XSS issue, meaning injected script may be retained and later executed when another user views affected content. The listed impact includes low confidentiality, integrity, and availability impact, and the scope may extend beyond the vulnerable component.
Which plugin versions are affected?
Affected versions are reported as Premium Addons for Elementor through version 4.11.109. No fixed version is provided in the available data.