CVE-2026-83541: Sina Extension for Elementor 3.7.1 - 3.10.3 - Contributor+ Stored XSS via Table Widget
The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before outputting it within an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated WordPress user with the Contributor role or a higher-privileged role can exploit it. The issue is relevant where untrusted or insufficiently trusted users can create or edit content using the plugin's Table widget.
What versions should be remediated?
Versions 3.7.1 through 3.10.3 are affected. Upgrade to version 3.10.4 or later.
What is required for exploitation?
The attacker needs an account with at least Contributor permissions and must be able to supply a malicious value for the affected Table widget setting. The payload is stored and executes when the affected content is viewed.