CVE-2026-96829: WordPress The Plus Addons for Elementor Page Builder Lite plugin <= 6.5.1 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
The Plus Addons for Elementor Page Builder Liteto a version that resolves this vulnerability.Fixed in 6.5.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs Contributor-level access to a WordPress site using the affected plugin. Exploitation also requires a user to interact with attacker-controlled content.
What versions are affected?
The issue affects The Plus Addons for Elementor Page Builder Lite versions 6.5.1 and earlier.
What is the potential impact?
Successful exploitation can execute cross-site scripting in a victim’s browser. The reported impact includes low confidentiality, integrity, and availability effects, and the vulnerability can affect a different security scope.