CVE-2026-94500: WordPress ElementsKit Elementor addons Lite plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability
Published Sep 23, 2026
·Updated
Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.
Affected Software
1 affected component
ElementsKit Elementor addons Lite<=4.0.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ElementsKit Elementor addons Liteto a version that resolves this vulnerability.Fixed in 4.0.6
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who needs to be authenticated to exploit this issue?
An attacker needs Contributor-level access. The available information does not indicate that unauthenticated visitors can exploit it.
2
Does exploitation require victim interaction?
Yes. The CVSS vector includes UI:R, indicating that user interaction is required for exploitation.
3
What impact can successful exploitation have?
The vulnerability can affect confidentiality, integrity, and availability at a low level, and its scope is changed, meaning the impact may extend beyond the vulnerable plugin's security authority.