CVE-2026-66574: WordPress Element Pack Elementor Addons plugin <= 8.8.3 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Element Pack Elementor Addonsto a version that resolves this vulnerability.Fixed in 8.8.4
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue is described as contributor XSS, so an attacker needs Contributor-level access to the affected WordPress site. User interaction is also required for exploitation.
Which installations are affected?
WordPress sites using Element Pack Elementor Addons version 8.8.3 or earlier are affected according to the available data.
What is the potential impact?
The supplied CVSS vector indicates low impacts to confidentiality, integrity, and availability, with scope changed. Because this is XSS, successful exploitation could run attacker-controlled script in a victim's browser context.