CVE-2026-105873: WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 8.8.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
bdthemes-element-pack-liteto a version that resolves this vulnerability.Fixed in 8.8.7
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs low-level privileges and can exploit the issue over the network with low attack complexity. Exploitation also requires user interaction with attacker-controlled content.
What is the expected impact if exploitation succeeds?
The vulnerability is a stored XSS issue with low confidentiality, integrity, and availability impact. The CVSS vector indicates the impact may extend beyond the vulnerable component because the scope is changed.