CVE-2026-87777: Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is at risk from the payload?
A user with at least Contributor-level access can inject the script payload. The payload executes when a higher-privileged user opens the affected content in the Elementor editor preview.
Which versions should be remediated?
Hostinger Reach versions before 1.8.3 are affected. Update to version 1.8.3 or later.
What can be done if the plugin cannot be updated immediately?
Restrict Contributor-level and other untrusted users from creating or editing content containing the affected Elementor widget. Higher-privileged users should avoid opening untrusted affected content in the editor until remediation is applied.