CVE-2026-105871: WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability
Published Oct 7, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 8.8.6.
Affected Software
1 affected component
BdThemes Element Pack Elementor Addons<=8.8.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
bdthemes-element-pack-liteto a version that resolves this vulnerability.Fixed in 8.8.7
Event History
Oct 7, 2026
CVE Published
via MITRE·09:04 AM
Data Sourced
via MITRE·09:04 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness